kotlin-multiplatform-layout-system

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from project source code and external HTML/CSS wireframes to create documentation and scaffolds, which is a standard functional requirement for layout design tasks.
  • Ingestion points: SKILL.md instructs the agent to read existing project source and HTML designs for translation into the layout system.
  • Boundary markers: The skill does not explicitly specify boundary markers in the generated documentation files to isolate external content.
  • Capability inventory: The skill is limited to local file system writes within the docs/layout-system/ directory and designated UI modules.
  • Sanitization: generate_slot_scaffold.py performs regex-based sanitization of identifiers and validates layout weights against a closed whitelist.
  • [DYNAMIC_EXECUTION]: The generate_slot_scaffold.py script generates Kotlin source code by interpolating metadata from markdown files into code templates.
  • Evidence: The generate_kotlin function in scripts/generate_slot_scaffold.py constructs a Kotlin file string using values parsed from the layout contract frontmatter.
  • Mitigation: The script uses the pascal() function with a restrictive regex re.split(r"[^a-zA-Z0-9]+", name) to sanitize class names and ensures layout weights are members of a predefined ALLOWED_WEIGHTS set.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 05:47 AM
Security Audit — agent-trust-hub — kotlin-multiplatform-layout-system