kotlin-android-push
Fail
Audited by Gen Agent Trust Hub on Jun 21, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill specifies a dependency on a package named
kotlin-androidto be installed vianpm. Standard Kotlin and Android development tools are managed through Gradle or the Android SDK, making the use ofnpmfor this purpose highly unusual and characteristic of supply chain attacks. - [COMMAND_EXECUTION]: The provided instructions include running
npm install kotlin-androidandkotlin-android --version. These commands result in the download and execution of code from a package that does not belong to the official development ecosystem for the described tasks.
Recommendations
- AI detected serious security threats
Audit Metadata