kotlin-multiplatform-push-notifications
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references the Firebase Bill of Materials (BoM) from Google's official repositories. This is a standard and safe practice for managing Android and iOS dependencies from a well-known service provider.
- [COMMAND_EXECUTION]: The skill defines standard Android and iOS lifecycle events, such as intent filters and service declarations in the AndroidManifest.xml, which are required for push notification functionality.
- [DATA_EXFILTRATION]: The skill describes the collection of push tokens and sending them to a backend server. This is the intended and primary purpose of the skill and is implemented using best practices like Android's WorkManager to ensure reliable delivery.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data from notification payloads. While this constitutes an attack surface, the provided code uses standard platform APIs and does not interpolate the content into instructions that could override agent behavior. Boundary markers are inherently managed by the platform's notification data structures (Intent extras on Android and userInfo dictionary on iOS).
Audit Metadata