kmp-layout-system
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill includes instructions for the agent to ingest external HTML/CSS wireframes to generate documentation and code. This creates an attack surface for indirect prompt injection.\n
- Ingestion points: External design files (e.g.,
design/wireframes/*.html) as described in the translation guide inSKILL.md.\n - Boundary markers: The instructions provide clear structural mapping and advise verifying component signatures, which helps mitigate accidental instruction following.\n
- Capability inventory: The skill writes documentation to
docs/layout-system/and generates Kotlin code to user-defined paths.\n - Sanitization:
create_wireframe.pyimplements XML-escaping for SVG labels, andgenerate_slot_scaffold.pyvalidates layout weights against a strict whitelist.\n- [DYNAMIC_EXECUTION]: The skill usesgenerate_slot_scaffold.pyto create Kotlin layout code from a YAML-defined contract.\n - The generator uses string templates and validates all input parameters (slots, grid mapping, and weights) against allowed sets, ensuring that generated code follows a safe, predictable structure.
Audit Metadata