compose-views-interop
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands such as
rg(ripgrep) to audit local Kotlin source code for specific interoperability patterns. It also suggests using anandroidCLI tool for searching and fetching documentation. These commands are primarily read-only and intended for developer assistance. - [EXTERNAL_DOWNLOADS]: The skill suggests fetching documentation from
developer.android.com, which is a well-known and trusted service for Android development. The use ofandroid docs fetchindicates potential network retrieval of instructional content. - [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection because it ingests untrusted data from the user's project files during the auditing process.
- Ingestion points: The output of
rg(ripgrep) commands when scanning local Kotlin source files is returned to the agent's context (SKILL.md). - Boundary markers: The suggested audit commands do not include explicit instructions or delimiters to warn the agent that the tool output should be treated strictly as data and not as instructions.
- Capability inventory: The skill uses
rgfor file searching and suggestsandroid docsfor documentation retrieval; it does not exhibit high-risk capabilities like file writing or unauthorized network exfiltration. - Sanitization: There is no evidence of sanitization or filtering applied to the source code snippets captured by the audit commands before they are processed by the agent.
Audit Metadata