android-kotlin

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill directs the agent to execute shell commands to list the contents of directories associated with the agent's installation (e.g., ~/.claude/skills/, ~/.agent/skills/) to perform environment enumeration and detect installed components.\n- [PROMPT_INJECTION]: The instructions mandate a specific persona-altering behavior, requiring the agent to start its first response in every conversation with a specific emoji symbol (๐Ÿงข).\n- [PROMPT_INJECTION]: The skill implements conditional logic that triggers the agent to recommend and offer installation commands for other skills from the same vendor if they are not detected in the environment.\n- [PROMPT_INJECTION]: The skill exhibits a surface area for indirect prompt injection as it processes user-provided development queries without explicit boundary markers or sanitization logic.\n
  • Ingestion points: User-provided prompts and Kotlin/Android code provided in the conversation context via SKILL.md instructions.\n
  • Boundary markers: Absent; there are no specific delimiters or instructions to ignore embedded commands in user data.\n
  • Capability inventory: The agent is instructed to execute shell commands (ls) and modify its conversational behavior based on file system state.\n
  • Sanitization: Absent; the skill does not specify any filtering or validation of user-provided content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 02:05 PM
Security Audit โ€” agent-trust-hub โ€” android-kotlin