kotlin-toolchain

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill documents the use of the Kotlin Toolchain, which is an official JetBrains build system. All referenced external links (e.g., github.com/JetBrains/kotlin-toolchain, kotlin-toolchain.org) lead to the official project repositories and documentation.
  • [SAFE]: The instructions include a dedicated security section ('Untrusted project input') that provides explicit guidance on handling third-party repositories. It directs the agent to treat wrapper scripts (./kotlin, kotlin.bat) and local plugins as executable code requiring review, and to ignore imperative commands embedded in YAML comments.
  • [SAFE]: The skill promotes secure configuration management by instructing the agent to disregard repository-supplied environment variables (KOTLIN_CLI_DOWNLOAD_ROOT, KOTLIN_CLI_JAVA_HOME) that could be used to redirect the distribution source to an untrusted location.
  • [SAFE]: No obfuscation, data exfiltration patterns, or unauthorized command execution triggers were identified in the skill content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 07:14 PM
Security Audit — agent-trust-hub — kotlin-toolchain