compose-screen-splitter
Pass
Audited by Gen Agent Trust Hub on Jun 21, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill employs standard system utilities such as
wc,awk, andgrepto perform structural audits of Kotlin source files. It additionally executes the project's local Gradle wrapper (./gradlew) to verify that refactoring actions maintain code integrity and pass existing tests. - [PROMPT_INJECTION]: The skill demonstrates a surface for indirect prompt injection by reading and processing the contents of external source files to determine its refactoring logic.
- Ingestion points: User-specified Kotlin source files (
*Screen.kt) in the project directory. - Boundary markers: Uses specific code fences like
// region Previewsto segment file content. - Capability inventory: Includes file system read, write, and edit permissions, along with the ability to execute shell commands and the project build system.
- Sanitization: The skill performs pattern matching on file content but does not explicitly sanitize or escape the ingested code before using it to generate refactoring proposals.
Audit Metadata