kotlin-specialist

Fail

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides a documentation link (https://jeffallan.github.io/claude-skills/skills/language/kotlin-specialist/) that has been identified as malicious and blacklisted by automated scanners.- [REMOTE_CODE_EXECUTION]: The manifest file SKILL.md is flagged as FileRepMalware by reputation scanners, indicating the presence of malicious content or serving as a vector for malicious payloads.- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to load detailed guidance from external documentation sources; since the associated URL is blacklisted, this creates a vulnerability where the agent may ingest malicious instructions, deceptive patterns, or unsafe code snippets. Mandatory Evidence Chain: 1. Ingestion points: Documentation links in SKILL.md; 2. Boundary markers: Absent; 3. Capability inventory: Command execution (detekt, ktlint) and code generation; 4. Sanitization: Absent.- [COMMAND_EXECUTION]: The skill workflow requires the agent to execute specific CLI tools (detekt, ktlint) which could be manipulated via malicious configurations served from the blacklisted external resources.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 15, 2026, 01:20 PM
Security Audit — agent-trust-hub — kotlin-specialist