gradle-to-kotlin-toolchain-plugin

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill instructs the agent to analyze untrusted project data from Gradle repositories, which represents an indirect prompt injection surface. Evidence: The workflow involves reading source plugin documentation, build scripts, and tests. Mitigations: The skill includes a clear security warning to treat repository-supplied input as untrusted and to review logic before integration.
  • [EXTERNAL_DOWNLOADS]: The code examples reference standard Maven dependencies required for Git integration and security. Evidence: Maven coordinates for org.eclipse.jgit and org.bouncycastle are listed in the reference examples. These are well-known and reputable libraries.
  • [COMMAND_EXECUTION]: The documentation includes shell command examples for validating plugin behavior in a development environment. Evidence: Commands such as ./kotlin run and git init are provided for user-led validation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 07:15 PM
Security Audit — agent-trust-hub — gradle-to-kotlin-toolchain-plugin