kmp-deep-linking

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides standard implementation templates for cross-platform deep linking including path parsing and route navigation.
  • [DATA_EXFILTRATION]: No sensitive data access or unauthorized external network transmission patterns were identified. All URLs used in the code examples and configuration templates are standard placeholders (e.g., example.com).
  • [REMOTE_CODE_EXECUTION]: The skill does not perform any remote code downloads, package installations, or dynamic command execution. Code is purely declarative for navigation logic.
  • [PROMPT_INJECTION]: No prompt injection patterns, role-play overrides, or instructions to bypass safety guidelines were detected in the skill metadata or body.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines an attack surface by ingesting external URLs (Category 8). However, it implements strong boundary markers and sanitization via regex-based parsing in DeepLinkParser.kt and restricts capabilities to internal app navigation using the NavController. This significantly mitigates risks of malicious URL input causing unintended actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 05:49 AM
Security Audit — agent-trust-hub — kmp-deep-linking