kotlin-java-migration-testing
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes project source code and assets which constitutes a data ingestion surface for potential indirect instructions.
- Ingestion points: The
scripts/audit_migration_tests.pyutility reads file content and calculates hashes for Java and Kotlin test files located in project directories provided as command-line arguments. - Boundary markers: There are no explicit boundary markers or 'ignore' instructions defined for the data processed by the audit script.
- Capability inventory: The included scripts are restricted to read-only auditing (regex matching and SHA-256 hashing). The skill instructions describe standard build and test execution workflows using Gradle.
- Sanitization: The skill does not implement specific sanitization or filtering of the content within the files being audited.
Audit Metadata