kotlin-multiplatform-token-saver
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides automated scripts to download and install third-party software using reputable package managers. Specifically,
scripts/install-rtk.shusesbrew install rtkandscripts/install-headroom.shusespip install headroom-ai. - [COMMAND_EXECUTION]: The skill utilizes official CLI subcommands to manage environment extensions.
scripts/install-ponytail.shexecutesclaude plugin installto register a third-party plugin at the user scope. - [COMMAND_EXECUTION]: The skill performs dry-runs to preview potential changes to the host environment.
scripts/install-rtk.shexecutesrtk init -g --dry-runto display a diff of proposed changes to global configuration files without applying them. - [DATA_EXFILTRATION]: The skill instructions and scripts manage references to sensitive configuration files such as
~/.claude/settings.json. However, the skill implements strong guardrails: it explicitly forbids the agent from handling user API keys and requires the user to manually perform any configuration edits involving credentials or global shell hooks. - [EXTERNAL_DOWNLOADS]: The documentation identifies a high-risk installation method (
curl | bash) for the 'Caveman' tool. It includes a mandatory security rule forbidding the agent from executing this installer, instead directing the user to review and run it manually in their terminal. - [PROMPT_INJECTION]: No malicious prompt injection patterns were detected. The skill instructions focus on adding safety-oriented anti-patterns and implementation guardrails rather than overriding agent behavior.
Audit Metadata