kotlin-compiler-plugin-dev
Pass
Audited by Gen Agent Trust Hub on Apr 27, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references source code and documentation from well-known and trusted GitHub repositories including the official Kotlin repository (JetBrains), KSP (Google), Anvil (Square), and Zipline (CashApp). These references are used solely for educational and architectural guidance.
- [REMOTE_CODE_EXECUTION]: The instructions include usage of a tool named
mcp__deepwiki__ask_questionto perform deep-dive questions into external source code repositories. This tool is used for technical discovery and informational reporting, not for executing untrusted payloads or commands. - [PROMPT_INJECTION]: Analysis of the skill instructions and reference materials found no evidence of prompt injection attempts, bypass markers, or instructions to ignore safety protocols.
- [DATA_EXFILTRATION]: There are no patterns indicating access to sensitive local files (like SSH keys or AWS credentials) or unauthorized transmission of data to external domains.
- [COMMAND_EXECUTION]: The skill focuses on providing design advice and reviewing code logic. It does not contain or suggest the execution of arbitrary shell commands or privilege escalation techniques.
Audit Metadata