kmp-push-notifications

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references and utilizes official Firebase libraries (com.google.firebase:firebase-bom and com.google.firebase:firebase-messaging) to provide notification functionality. These dependencies are from a well-known service and represent standard implementation practices for the skill's stated purpose.- [PROMPT_INJECTION]: The skill exposes a potential surface for indirect prompt injection by processing external data from push notifications and routing it to application logic via deep links.
  • Ingestion points: The skill ingests untrusted data from the network in AppFirebaseMessagingService.kt (onMessageReceived) and AppDelegate.swift (userNotificationCenter).
  • Boundary markers: There are no explicit boundary markers or instructions to ignore embedded commands within the notification data handling code.
  • Capability inventory: The skill utilizes a DeepLinkEventBus to emit routes based on external data, which influences application navigation and behavior.
  • Sanitization: The provided code snippets do not implement sanitization or validation logic for the 'deepLink' string before it is processed by the DeepLinkParser.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 05:50 AM
Security Audit — agent-trust-hub — kmp-push-notifications