earllm-build

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill functions as a project-specific knowledge base for Android development, providing architectural context and technical facts for the EarLLM One project.
  • [COMMAND_EXECUTION]: Includes standard shell commands for Gradle builds and project archiving using PowerShell. These commands are intended for local project maintenance and follow established development practices for generating artifacts and running tests.
  • [DATA_EXPOSURE]: Contains a hardcoded local project path (C:\Users\renat\earbudllm). While this reveals a local directory structure and username, it is used for environment configuration and does not expose sensitive credentials, private keys, or secrets. The skill correctly references the use of SecureTokenStore.kt and EncryptedSharedPreferences for managing API keys.
  • [PROMPT_INJECTION]: No override instructions, bypass attempts, or system prompt extraction patterns were identified in the instructions or metadata.
  • [EXTERNAL_DOWNLOADS]: No remote script downloads or unverified external package installations are defined; all dependencies mentioned are standard Android/Kotlin libraries.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 04:26 PM
Security Audit — agent-trust-hub — earllm-build