kotlin-specialist
Fail
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references 'https://jeffallan.github.io/claude-skills/skills/language/kotlin-specialist/' for documentation, which is explicitly flagged as a blacklisted and malicious URL by automated scanners.
- [METADATA_POISONING]: The main skill file 'SKILL.md' is flagged by reputation scanners as malicious (FileRepMalware). Furthermore, the author URL in the metadata points to a GitHub profile 'Jeffallan', which is inconsistent with the skill's reported author 'sodiqabdulwaris'.
- [INDIRECT_PROMPT_INJECTION]: The skill acts on user-provided application requirements to generate complex Kotlin code for KMP, Android, and Ktor. It does not implement boundary markers or instructions to ignore potential commands embedded in project specifications, creating a surface for code generation manipulation.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata