jetpack-compose-m3

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches library versioning information from Google's official Maven repository (dl.google.com). This is a well-known, trusted source used to identify the latest stable version of the Wear Compose library.
  • [COMMAND_EXECUTION]: Instructs the agent to use shell commands including 'find' to locate JAR files in the Gradle cache and 'unzip' to extract them to a local workspace. These operations are performed to facilitate the analysis of official documentation and samples.
  • [DATA_EXFILTRATION]: Accesses sensitive paths in the Gradle user home directory (e.g., ~/.gradle) to locate library modules. The skill uses this data locally for context and does not include any instructions or patterns to transmit this information to external servers.
  • [PROMPT_INJECTION]: Employs strong instructional language ('STRICT COMPLIANCE', 'FORBIDDEN') to mandate a specific environment setup (extracting samples) before code generation. These are operational constraints rather than malicious attempts to bypass safety filters or extract system instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 10:16 AM
Security Audit — agent-trust-hub — jetpack-compose-m3