networking-retrofit-ktor
Pass
Audited by Gen Agent Trust Hub on Jul 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill instructions emphasize security best practices, specifically instructing the agent to 'Do not log tokens or secrets' and to avoid logging sensitive headers like 'Authorization'.
- [SAFE]: All identified commands (
./gradlew test,./gradlew assembleDebug,./gradlew lint) are standard local build and testing commands for the Android/Gradle ecosystem. - [SAFE]: The skill identifies an attack surface for Indirect Prompt Injection by reading project files and API contracts; however, it lacks high-risk capabilities like arbitrary shell execution or network exfiltration that would elevate the risk beyond a standard development assistant profile.
- [SAFE]: No external dependencies, remote script downloads, or obfuscated contents were found in the analyzed files.
Audit Metadata