kotlin-multiplatform-roborazzi

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references standard development dependencies including the io.github.takahirom.roborazzi library and well-known GitHub Actions such as actions/checkout, actions/setup-java, and gradle/actions/setup-gradle. These are legitimate resources from established maintainers.
  • [COMMAND_EXECUTION]: Instructions include running standard Gradle tasks like ./gradlew jvmTest and ./gradlew recordRoborazziJvm, as well as project-specific CLI tools like /kmm-audit-screenshots. These commands are appropriate for the skill's stated purpose of automating UI tests and visual audits.
  • [DATA_EXFILTRATION]: The provided GitHub Actions workflow correctly uses GitHub Secrets (secrets.GRADLE_ENCRYPTION_KEY) for sensitive configuration, which is a recommended security practice for CI/CD environments.
  • [PROMPT_INJECTION]: The skill mentions a visual design audit using vision models to evaluate screenshots. While processing external images can be a surface for indirect prompt injection, the skill context is restricted to evaluating UI components against a design system, which is a low-risk application of the technology.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 03:15 AM
Security Audit — agent-trust-hub — kotlin-multiplatform-roborazzi