kmp-compose-animation
Warn
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: MEDIUMMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
- [METADATA_POISONING]: The skill metadata contains misleading authorship information; the SKILL.md frontmatter identifies the author as 'kmp-agent-skills', which conflicts with the authoritative author context identifying 'ronjunevaldoz'.
- [INDIRECT_PROMPT_INJECTION]: The skill implementation demonstrates patterns for ingesting external data (image URLs), establishing a vulnerability surface for indirect prompt injection attacks.
- Ingestion points: External image URLs are ingested via the 'product.imageUrl' property within the 'ProductListItem' and 'ProductDetailContent' composables.
- Boundary markers: No boundary markers or explicit instructions to ignore potentially malicious embedded content are provided in the skill instructions.
- Capability inventory: The skill is restricted to UI animation logic and does not incorporate dangerous capabilities such as subprocess execution, file system modifications, or direct network requests.
- Sanitization: The logic relies on standard library handling for URLs and does not include custom input validation or sanitization routines.
Audit Metadata