kotlin-multiplatform-design-system
Pass
Audited by Gen Agent Trust Hub on Aug 1, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill provides several Python scripts (
derive_component_prefix.py,generate_palette.py,scaffold_preview_coverage.py,scan_design_violations.py,update_design_system.py) that the agent is instructed to execute. These scripts perform local file system operations, such as reading project configuration files (Gradle settings) and source code, as well as writing generated boilerplate and test files. These actions are standard for a code scaffolding and maintenance tool and do not involve network connectivity or unauthorized data access. - [EXTERNAL_DOWNLOADS]: The documentation references external repositories and libraries authored by the skill's creator (
ronjunevaldoz), specificallytailwind-composeandshadcn-compose. These are recognized as legitimate vendor resources for the intended use case of design system development. - [INDIRECT_PROMPT_INJECTION]: The skill's scripts and instructions involve reading and processing untrusted data from the user's project, such as
docs/design-system.mdand Kotlin source files. While this creates a potential attack surface, the scripts use this data for well-defined, programmatic tasks (regex parsing, PSI analysis, MD5 comparisons) rather than direct prompt interpolation that could override agent instructions. The risk is minimized by the skill's design, which emphasizes user confirmation for modifications.
Audit Metadata