kotlin-android-push

Fail

Audited by Gen Agent Trust Hub on Jun 21, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill specifies a dependency on a package named kotlin-android to be installed via npm. Standard Kotlin and Android development tools are managed through Gradle or the Android SDK, making the use of npm for this purpose highly unusual and characteristic of supply chain attacks.
  • [COMMAND_EXECUTION]: The provided instructions include running npm install kotlin-android and kotlin-android --version. These commands result in the download and execution of code from a package that does not belong to the official development ecosystem for the described tasks.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jun 21, 2026, 04:50 PM
Security Audit — agent-trust-hub — kotlin-android-push