kotlin-specialist

Fail

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references 'https://jeffallan.github.io/claude-skills/skills/language/kotlin-specialist/' for documentation, which is explicitly flagged as a blacklisted and malicious URL by automated scanners.
  • [METADATA_POISONING]: The main skill file 'SKILL.md' is flagged by reputation scanners as malicious (FileRepMalware). Furthermore, the author URL in the metadata points to a GitHub profile 'Jeffallan', which is inconsistent with the skill's reported author 'sodiqabdulwaris'.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts on user-provided application requirements to generate complex Kotlin code for KMP, Android, and Ktor. It does not implement boundary markers or instructions to ignore potential commands embedded in project specifications, creating a surface for code generation manipulation.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 5, 2026, 11:38 AM
Security Audit — agent-trust-hub — kotlin-specialist