kmp-compose-preview-driven-development

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The instructions are limited to technical development workflows and do not attempt to override AI safety guidelines or extract system prompts.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: No evidence of sensitive file access or network exfiltration was found. Data examples provided, such as email addresses and user IDs, are standard placeholders for development tutorials.
  • [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: All mentioned commands, such as './gradlew :desktopApp:run', are standard build tool operations required for the documented development process. No untrusted third-party scripts or packages are included.
  • [OBFUSCATION]: The content is clear and does not use Base64, zero-width characters, or other techniques to hide malicious intent.
  • [INDIRECT_PROMPT_INJECTION]: 1. Ingestion points: UI state objects (AuthUiState) defined in SKILL.md and passed to composables. 2. Boundary markers: Absent. 3. Capability inventory: Includes shell command execution via Gradle build scripts mentioned in SKILL.md. 4. Sanitization: Absent, which is standard for UI component code.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 05:50 AM
Security Audit — agent-trust-hub — kmp-compose-preview-driven-development