kotlin-multiplatform-legal-docs

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill represents an indirect prompt injection surface because it processes untrusted data from the user's project source code through a scanning script.
  • Ingestion points: The detect_data_collection.py script reads project files including *.kt, *.swift, *.xml, and libs.versions.toml, extracting code snippets as evidence.
  • Boundary markers: The skill does not define specific delimiters or instructions to isolate the ingested project data from the agent's core instructions.
  • Capability inventory: The agent uses the scan results to generate Markdown templates for Privacy Policies and Terms & Conditions, and Kotlin UI code. It does not perform high-privilege actions based on this data.
  • Sanitization: The script truncates extracted evidence snippets to 80 characters, which provides a limited form of sanitization for ingested strings.
  • [COMMAND_EXECUTION]: The skill requires the execution of a bundled Python script (detect_data_collection.py) to perform its primary function. The script uses standard libraries and regex-based scanning to analyze the local project directory without initiating network connections or accessing system-level sensitive files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 03:15 AM
Security Audit — agent-trust-hub — kotlin-multiplatform-legal-docs