gradle-to-kotlin-toolchain-plugin
Pass
Audited by Gen Agent Trust Hub on Aug 23, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill instructs the agent to analyze untrusted project data from Gradle repositories, which represents an indirect prompt injection surface. Evidence: The workflow involves reading source plugin documentation, build scripts, and tests. Mitigations: The skill includes a clear security warning to treat repository-supplied input as untrusted and to review logic before integration.
- [EXTERNAL_DOWNLOADS]: The code examples reference standard Maven dependencies required for Git integration and security. Evidence: Maven coordinates for org.eclipse.jgit and org.bouncycastle are listed in the reference examples. These are well-known and reputable libraries.
- [COMMAND_EXECUTION]: The documentation includes shell command examples for validating plugin behavior in a development environment. Evidence: Commands such as ./kotlin run and git init are provided for user-led validation.
Audit Metadata