compose-project

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references the official Gradle distribution at services.gradle.org within the gradle-wrapper.properties template. This is a well-known official service. The configuration includes a distributionSha256Sum to ensure the integrity of the downloaded ZIP file.
  • [COMMAND_EXECUTION]: The skill includes a read-only audit script, scripts/audit-project.sh, designed to scan project files for kit compliance. The script uses standard utilities like find and grep and does not perform network operations or modify files.
  • [REMOTE_CODE_EXECUTION]: The provided GitHub Actions CI template (composekit.yml) utilizes official and trusted actions, including actions/checkout, actions/setup-java, and gradle/actions/wrapper-validation, to perform verification and validation tasks.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and generate project configuration files (e.g., build.gradle.kts, libs.versions.toml). While this involves reading developer-controlled data, the risk is mitigated by explicit non-negotiable instructions requiring the agent to verify all coordinates and DSL blocks against official documentation rather than relying on recalled information.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 06:19 PM
Security Audit — agent-trust-hub — compose-project