kotlin-specialist
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill workflow (SKILL.md, Step 4) directs the execution of external tools
detektandktlintto validate code. While these are standard static analysis tools for the Kotlin ecosystem, they represent a command execution surface where the agent is instructed to run shell commands based on the project state. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze and implement Kotlin code provided by the user, which presents an indirect prompt injection surface where malicious instructions could be embedded in code comments or string literals.
- Ingestion points: User-provided Kotlin source code, architectural designs, and platform targets described in the 'Core Workflow' section of
SKILL.md. - Boundary markers: The skill instructions do not define specific delimiters or instructions to ignore embedded commands within the processed Kotlin code or configuration files.
- Capability inventory: The skill has the capability to write code, modify files, and run external command-line tools (
detekt,ktlint) as part of its validation step. - Sanitization: There is no explicit requirement or mechanism mentioned to sanitize or escape content from the analyzed code before it influences the agent's output or command execution.
Audit Metadata