kmp-compose-animation

Warn

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: MEDIUMMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
  • [METADATA_POISONING]: The skill metadata contains misleading authorship information; the SKILL.md frontmatter identifies the author as 'kmp-agent-skills', which conflicts with the authoritative author context identifying 'ronjunevaldoz'.
  • [INDIRECT_PROMPT_INJECTION]: The skill implementation demonstrates patterns for ingesting external data (image URLs), establishing a vulnerability surface for indirect prompt injection attacks.
  • Ingestion points: External image URLs are ingested via the 'product.imageUrl' property within the 'ProductListItem' and 'ProductDetailContent' composables.
  • Boundary markers: No boundary markers or explicit instructions to ignore potentially malicious embedded content are provided in the skill instructions.
  • Capability inventory: The skill is restricted to UI animation logic and does not incorporate dangerous capabilities such as subprocess execution, file system modifications, or direct network requests.
  • Sanitization: The logic relies on standard library handling for URLs and does not include custom input validation or sanitization routines.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 28, 2026, 10:23 AM
Security Audit — agent-trust-hub — kmp-compose-animation