compose-ui
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to review and modify Android/KMP source code. This creates a surface for indirect prompt injection if the user-provided code contains malicious instructions intended to influence the agent's behavior.
- Ingestion points: The skill processes user-supplied Kotlin/Compose source code files during review and editing tasks.
- Boundary markers: There are no explicit instructions for the agent to treat user-provided code as untrusted or to use specific delimiters to separate code from instructions.
- Capability inventory: The agent is authorized to search the codebase using
rgand is expected to generate or modify code based on the provided guidelines. - Sanitization: No explicit sanitization or filtering of the input code content is performed.
- [SAFE]: All external URLs referenced in the skill point to official documentation from trusted organizations, including Google (Android/Material Design) and JetBrains (Kotlin/Compose Multiplatform).
- Evidence:
https://m3.material.io/styles/color/roles(Google/Material Design)https://developer.android.com/develop/ui/compose/performance/stability/strongskipping(Google)https://kotlinlang.org/docs/whatsnew2020.html(JetBrains)- [SAFE]: The skill uses standard command-line tools like
rg(ripgrep) solely for the purpose of auditing code quality and ensuring compliance with the defined architectural rules (e.g., checking for hardcoded colors or ViewModel usage).
Audit Metadata