jetpack-compose-m3
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches library versioning information from Google's official Maven repository (dl.google.com). This is a well-known, trusted source used to identify the latest stable version of the Wear Compose library.
- [COMMAND_EXECUTION]: Instructs the agent to use shell commands including 'find' to locate JAR files in the Gradle cache and 'unzip' to extract them to a local workspace. These operations are performed to facilitate the analysis of official documentation and samples.
- [DATA_EXFILTRATION]: Accesses sensitive paths in the Gradle user home directory (e.g., ~/.gradle) to locate library modules. The skill uses this data locally for context and does not include any instructions or patterns to transmit this information to external servers.
- [PROMPT_INJECTION]: Employs strong instructional language ('STRICT COMPLIANCE', 'FORBIDDEN') to mandate a specific environment setup (extracting samples) before code generation. These are operational constraints rather than malicious attempts to bypass safety filters or extract system instructions.
Audit Metadata