kotlin-toolchain
Pass
Audited by Gen Agent Trust Hub on Aug 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill documents the use of the Kotlin Toolchain, which is an official JetBrains build system. All referenced external links (e.g.,
github.com/JetBrains/kotlin-toolchain,kotlin-toolchain.org) lead to the official project repositories and documentation. - [SAFE]: The instructions include a dedicated security section ('Untrusted project input') that provides explicit guidance on handling third-party repositories. It directs the agent to treat wrapper scripts (
./kotlin,kotlin.bat) and local plugins as executable code requiring review, and to ignore imperative commands embedded in YAML comments. - [SAFE]: The skill promotes secure configuration management by instructing the agent to disregard repository-supplied environment variables (
KOTLIN_CLI_DOWNLOAD_ROOT,KOTLIN_CLI_JAVA_HOME) that could be used to redirect the distribution source to an untrusted location. - [SAFE]: No obfuscation, data exfiltration patterns, or unauthorized command execution triggers were identified in the skill content.
Audit Metadata