kmp-layout-system

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill includes instructions for the agent to ingest external HTML/CSS wireframes to generate documentation and code. This creates an attack surface for indirect prompt injection.\n
  • Ingestion points: External design files (e.g., design/wireframes/*.html) as described in the translation guide in SKILL.md.\n
  • Boundary markers: The instructions provide clear structural mapping and advise verifying component signatures, which helps mitigate accidental instruction following.\n
  • Capability inventory: The skill writes documentation to docs/layout-system/ and generates Kotlin code to user-defined paths.\n
  • Sanitization: create_wireframe.py implements XML-escaping for SVG labels, and generate_slot_scaffold.py validates layout weights against a strict whitelist.\n- [DYNAMIC_EXECUTION]: The skill uses generate_slot_scaffold.py to create Kotlin layout code from a YAML-defined contract.\n
  • The generator uses string templates and validates all input parameters (slots, grid mapping, and weights) against allowed sets, ensuring that generated code follows a safe, predictable structure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 11:35 PM
Security Audit — agent-trust-hub — kmp-layout-system