sota-jvm

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill functions as a static knowledge base and set of instructions for the agent to use when writing or auditing JVM code. It does not contain any malicious scripts, hidden commands, or attempts to exfiltrate data. All external references are to trusted documentation sources like Oracle, Kotlin, and OWASP.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary purpose is to audit external source code, which constitutes an ingestion point for untrusted data. However, the instructions provide a strict framework for analysis, treating all input bytes as hostile and requiring evidence-based reporting, which mitigates the risk of the agent being manipulated by instructions inside the audited code. As per the security framework, this architectural surface is noted but does not escalate the verdict.
  • [COMMAND_EXECUTION]: The skill includes several grep command templates in its 'Audit checklist' sections. These are standard, safe shell utilities intended for local source code scanning and do not involve downloading or executing untrusted remote content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 10:17 PM
Security Audit — agent-trust-hub — sota-jvm