kotlin-tooling-agp9-migration

Warn

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: MEDIUMMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
  • [METADATA_POISONING]: The SKILL.md file identifies the author as 'JetBrains', which is deceptive as the actual skill author is 'midudev'. This falsely attributes the skill to a major software organization.
  • [INDIRECT_PROMPT_INJECTION]: The skill relies on reading and processing content from local project files, which could contain instructions designed to manipulate the agent's behavior.
  • Ingestion points: Project configuration files including build.gradle.kts, settings.gradle.kts, gradle/libs.versions.toml, and gradle.properties are read by the agent and analyzed by scripts/analyze-project.sh.
  • Boundary markers: The skill lacks explicit markers to differentiate between project data and instructions, making it susceptible to embedded commands in project files.
  • Capability inventory: The agent is authorized to execute shell scripts (scripts/analyze-project.sh) and perform significant file system modifications across multiple modules.
  • Sanitization: Data extracted from the project environment is not sanitized before being incorporated into the agent's decision-making process for the migration.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 17, 2026, 11:19 PM
Security Audit — agent-trust-hub — kotlin-tooling-agp9-migration