kmp-navigation
Pass
Audited by Gen Agent Trust Hub on Aug 8, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides standard boilerplate and configuration for Kotlin Multiplatform navigation. It correctly references the official JetBrains Navigation Compose fork (
org.jetbrains.androidx.navigation:navigation-compose) and the well-known Decompose library (com.arkivanov.decompose:decompose). - [DATA_EXPOSURE]: No hardcoded credentials, sensitive file path access, or unauthorized network operations were detected. All external URL references are to official documentation or placeholder domains (e.g.,
example.com). - [REMOTE_CODE_EXECUTION]: The skill does not contain any instructions for downloading and executing remote scripts. Dependencies are managed through standard Gradle version catalogs, which is a secure and recommended practice.
- [INDIRECT_PROMPT_INJECTION]: While the skill implements handlers for external inputs such as deep links and browser URL fragments (specifically in the WasmJs section), it promotes the use of type-safe routes via
kotlinx.serialization. This approach effectively sanitizes incoming navigation arguments into structured data, reducing the surface for injection attacks. - Ingestion points: Deep link intent filters in
AndroidManifest.xmlandwindow.location.hashinwasmJsMain. - Boundary markers: The implementation uses type-safe classes for routes, acting as a boundary for input validation.
- Capability inventory: The skill only handles UI navigation state within the application context.
- Sanitization: External strings are parsed into Kotlin data classes using
kotlinx.serialization, ensuring that only expected data structures are processed.
Audit Metadata