super-android-kotlin-firebase

Pass

Audited by Gen Agent Trust Hub on Jul 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The repository follows security best practices for AI agent skills. It includes a SECURITY.md file that explicitly forbids committing secrets and a root SKILL.md that instructs agents never to request or expose private credentials. It also provides a security subskill focused on auditing projects for secret leaks.
  • [COMMAND_EXECUTION]: All shell commands included (e.g., Gradle tasks, Firebase emulator commands, and adb operations) are standard for Android development and necessary for the skill's stated purpose of building and testing apps. These are presented transparently for agent and user awareness.
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing companion skills and technical references from public repositories. These include trusted sources (official Android and Firebase repositories) and well-known community contributors. The skill explicitly advises users to review third-party content before use.
  • [PROMPT_INJECTION]: No malicious prompt injection or override patterns were detected. The guidelines provided are operational constraints that align agent behavior with safe software engineering practices, such as verifying builds before making UI changes.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 6, 2026, 12:30 PM
Security Audit — agent-trust-hub — super-android-kotlin-firebase