android-kotlin
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill directs the agent to execute shell commands to list the contents of directories associated with the agent's installation (e.g.,
~/.claude/skills/,~/.agent/skills/) to perform environment enumeration and detect installed components.\n- [PROMPT_INJECTION]: The instructions mandate a specific persona-altering behavior, requiring the agent to start its first response in every conversation with a specific emoji symbol (๐งข).\n- [PROMPT_INJECTION]: The skill implements conditional logic that triggers the agent to recommend and offer installation commands for other skills from the same vendor if they are not detected in the environment.\n- [PROMPT_INJECTION]: The skill exhibits a surface area for indirect prompt injection as it processes user-provided development queries without explicit boundary markers or sanitization logic.\n - Ingestion points: User-provided prompts and Kotlin/Android code provided in the conversation context via SKILL.md instructions.\n
- Boundary markers: Absent; there are no specific delimiters or instructions to ignore embedded commands in user data.\n
- Capability inventory: The agent is instructed to execute shell commands (
ls) and modify its conversational behavior based on file system state.\n - Sanitization: Absent; the skill does not specify any filtering or validation of user-provided content.
Audit Metadata