kotlin-tooling-gradle-to-kotlin-toolchain-plugin

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to ingest and analyze untrusted external project data, including README files, build scripts, and source code of existing plugins, which serves as an entry point for indirect prompt injection.
  • Ingestion points: The agent is instructed to catalog tasks, DSL surfaces, and CI integration from the source plugin's docs/, README.md, and build scripts (SKILL.md).
  • Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands within the analyzed data, although they do feature a general warning regarding untrusted project input.
  • Capability inventory: The skill facilitates file creation and modification (project.yaml, module.yaml, Kotlin source files) and the execution of project-specific commands (./kotlin run, ./kotlin do) (SKILL.md).
  • Sanitization: There are no explicit sanitization or validation steps provided for the agent to filter instructions that might be embedded in the analyzed plugin documentation or code.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 02:42 PM
Security Audit — agent-trust-hub — kotlin-tooling-gradle-to-kotlin-toolchain-plugin