kotlin-tooling-agp9-migration
Warn
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: MEDIUMMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
- [METADATA_POISONING]: The
SKILL.mdfile identifies the author as 'JetBrains', which is deceptive as the actual skill author is 'midudev'. This falsely attributes the skill to a major software organization. - [INDIRECT_PROMPT_INJECTION]: The skill relies on reading and processing content from local project files, which could contain instructions designed to manipulate the agent's behavior.
- Ingestion points: Project configuration files including
build.gradle.kts,settings.gradle.kts,gradle/libs.versions.toml, andgradle.propertiesare read by the agent and analyzed byscripts/analyze-project.sh. - Boundary markers: The skill lacks explicit markers to differentiate between project data and instructions, making it susceptible to embedded commands in project files.
- Capability inventory: The agent is authorized to execute shell scripts (
scripts/analyze-project.sh) and perform significant file system modifications across multiple modules. - Sanitization: Data extracted from the project environment is not sanitized before being incorporated into the agent's decision-making process for the migration.
Audit Metadata