gradle-to-kotlin-toolchain-project

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill requires the agent to ingest and process external project files, including Gradle build scripts, CI workflows, and version catalogs. This surface is vulnerable to indirect prompt injection if the project source is malicious.
  • Ingestion points: build.gradle.kts, gradle/libs.versions.toml, and CI workflow YAML files (SKILL.md, Phase 1).
  • Boundary markers: None provided; the skill refers to an external document for handling untrusted input.
  • Capability inventory: The skill utilizes file system write access for configuration generation and command execution for build tasks.
  • Sanitization: No explicit sanitization or filtering of input from Gradle files is described.
  • [COMMAND_EXECUTION]: The migration workflow relies on executing local build commands (e.g., ./kotlin build, ./kotlin check) and custom plugin tasks. These commands run code defined in the project and its plugins.
  • [DYNAMIC_EXECUTION]: The skill guides the authoring and vendoring of Kotlin-based build plugins. These plugins execute at build time with full filesystem and network access. The skill correctly warns the user to review any vendored code from GitHub before integration (SKILL.md, Phase 2).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 07:15 PM
Security Audit — agent-trust-hub — gradle-to-kotlin-toolchain-project