desktop/kde

Pass

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security concerns were detected. The skill instructions and code snippets align with legitimate KDE software development practices.
  • [COMMAND_EXECUTION]: The skill includes documentation for setting up development environments via standard Linux package managers (apt, dnf, pacman). These are neutrally documented as prerequisite steps for developers and do not constitute an exploit.
  • [PROMPT_INJECTION]: The skill features a development assistant model that processes project-specific context such as CMake configuration files and QML module dependencies. While this represents a theoretical surface for indirect prompt injection, it is intrinsic to the skill's primary purpose as a code engineering tool and follows standard agent protocols.
  • Ingestion points: User-provided CMake configuration files and QML module paths (SKILL.md).
  • Boundary markers: Absent.
  • Capability inventory: Suggests and generates CMake configuration, modifies C++ and QML source code, and configures DBus IPC interfaces (SKILL.md).
  • Sanitization: Not explicitly specified in the instructional text.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 8, 2026, 12:25 PM
Security Audit — agent-trust-hub — desktop/kde