houtu-dependencies
Pass
Audited by Gen Agent Trust Hub on Jun 21, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides instructions for the AI agent to generate Java code and configuration files based on the Houtu framework's conventions. This is the intended purpose and does not pose a security risk.
- [SAFE]: The use of the
git showcommand is documented as a mechanism for the agent to verify framework source code and API parameters. This is a standard practice for development-oriented agents. - [SAFE]: All suggested dependencies are legitimate Java libraries (e.g., Redisson, JJWT, Apache HttpClient) or vendor-specific resources from the author's group ID (io.github.lujiafa), which is consistent with the skill's context.
- [SAFE]: No prompt injection, obfuscation, or malicious data handling patterns were identified during the analysis.
- [SAFE]: Regarding potential indirect prompt injection, the skill ingests project configuration files (pom.xml, build.gradle) and user prompts to generate code. While this creates an attack surface, the instructions are focused on standard framework implementation and do not include high-risk capabilities or unsafe interpolation patterns.
Audit Metadata