compose-audit
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by processing external data.
- Ingestion points: Project source files are scanned using
rg(ripgrep) in Phase 2 of the workflow as defined inSKILL.mdandreferences/detection-catalog.md. - Boundary markers: The
assets/AUDIT-REPORT.mdtemplate uses Markdown code blocks (```kotlin) to encapsulate evidence snippets, providing structural separation but lacking explicit "ignore embedded instructions" warnings. - Capability inventory: The skill utilizes shell commands (
rg,find), theandroid-clifor documentation lookups, and the JetBrains-focusedcontext7MCP. - Sanitization: The instructions do not specify sanitization or escaping of the retrieved code snippets before they are interpolated into the final audit report.
- [COMMAND_EXECUTION]: The skill directs the agent to execute shell commands to perform its auditing functions.
- Evidence:
SKILL.mdandreferences/discovery-playbook.mddescribe the use offindandrgto discover project types and search for code patterns. - Context: These tools are standard for static analysis and are used here within a defined, hardcoded set of patterns.
Audit Metadata