compose-project
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references the official Gradle distribution at
services.gradle.orgwithin thegradle-wrapper.propertiestemplate. This is a well-known official service. The configuration includes adistributionSha256Sumto ensure the integrity of the downloaded ZIP file. - [COMMAND_EXECUTION]: The skill includes a read-only audit script,
scripts/audit-project.sh, designed to scan project files for kit compliance. The script uses standard utilities likefindandgrepand does not perform network operations or modify files. - [REMOTE_CODE_EXECUTION]: The provided GitHub Actions CI template (
composekit.yml) utilizes official and trusted actions, includingactions/checkout,actions/setup-java, andgradle/actions/wrapper-validation, to perform verification and validation tasks. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and generate project configuration files (e.g.,
build.gradle.kts,libs.versions.toml). While this involves reading developer-controlled data, the risk is mitigated by explicit non-negotiable instructions requiring the agent to verify all coordinates and DSL blocks against official documentation rather than relying on recalled information.
Audit Metadata