compose-audit

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by processing external data.
  • Ingestion points: Project source files are scanned using rg (ripgrep) in Phase 2 of the workflow as defined in SKILL.md and references/detection-catalog.md.
  • Boundary markers: The assets/AUDIT-REPORT.md template uses Markdown code blocks (```kotlin) to encapsulate evidence snippets, providing structural separation but lacking explicit "ignore embedded instructions" warnings.
  • Capability inventory: The skill utilizes shell commands (rg, find), the android-cli for documentation lookups, and the JetBrains-focused context7 MCP.
  • Sanitization: The instructions do not specify sanitization or escaping of the retrieved code snippets before they are interpolated into the final audit report.
  • [COMMAND_EXECUTION]: The skill directs the agent to execute shell commands to perform its auditing functions.
  • Evidence: SKILL.md and references/discovery-playbook.md describe the use of find and rg to discover project types and search for code patterns.
  • Context: These tools are standard for static analysis and are used here within a defined, hardcoded set of patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 05:32 AM
Security Audit — agent-trust-hub — compose-audit