crossfade-container-sizes-to-the-visible-child

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides shell commands that use find, javap, and grep to inspect local build artifacts and source code. This involves executing system utilities to analyze library implementation details and verify the framework's internal measure policies.
  • [DATA_EXPOSURE]: The verification scripts access the ~/.gradle/caches directory to locate specific library files (animation-desktop-*.jar). This behavior probes the filesystem for environmental metadata and dependency information.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes instructions to search all local Kotlin (.kt) files for specific patterns. This creates an attack surface where maliciously crafted content in processed source files could influence the agent's behavior.
  • Ingestion points: Local source files (*.kt) via grep command in the verification section.
  • Boundary markers: Absent.
  • Capability inventory: File system search (grep, find) and disassembly (javap).
  • Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 07:03 AM
Security Audit — agent-trust-hub — crossfade-container-sizes-to-the-visible-child