room-datastore

Pass

Audited by Gen Agent Trust Hub on Jul 6, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface typical of coding assistants.\n
  • Ingestion points: The agent is directed to inspect domain models, SQL queries, database versions, and existing migration files within the local project environment (SKILL.md).\n
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to distinguish between its own system instructions and potentially malicious natural language instructions embedded in code comments or data within the files it processes.\n
  • Capability inventory: The skill grants the agent capabilities to modify a wide range of project files (Room entities, DAO files, DataStore serializers) and to execute shell commands for building and testing the application via ./gradlew (SKILL.md).\n
  • Sanitization: The skill does not define or require any sanitization, validation, or escaping of the content ingested from files before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 6, 2026, 12:31 PM
Security Audit — agent-trust-hub — room-datastore