kotlin-multiplatform-roborazzi
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references standard development dependencies including the
io.github.takahirom.roborazzilibrary and well-known GitHub Actions such asactions/checkout,actions/setup-java, andgradle/actions/setup-gradle. These are legitimate resources from established maintainers. - [COMMAND_EXECUTION]: Instructions include running standard Gradle tasks like
./gradlew jvmTestand./gradlew recordRoborazziJvm, as well as project-specific CLI tools like/kmm-audit-screenshots. These commands are appropriate for the skill's stated purpose of automating UI tests and visual audits. - [DATA_EXFILTRATION]: The provided GitHub Actions workflow correctly uses GitHub Secrets (
secrets.GRADLE_ENCRYPTION_KEY) for sensitive configuration, which is a recommended security practice for CI/CD environments. - [PROMPT_INJECTION]: The skill mentions a visual design audit using vision models to evaluate screenshots. While processing external images can be a surface for indirect prompt injection, the skill context is restricted to evaluating UI components against a design system, which is a low-risk application of the technology.
Audit Metadata