kotlin-compiler-plugin-dev

Pass

Audited by Gen Agent Trust Hub on Apr 27, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references source code and documentation from well-known and trusted GitHub repositories including the official Kotlin repository (JetBrains), KSP (Google), Anvil (Square), and Zipline (CashApp). These references are used solely for educational and architectural guidance.
  • [REMOTE_CODE_EXECUTION]: The instructions include usage of a tool named mcp__deepwiki__ask_question to perform deep-dive questions into external source code repositories. This tool is used for technical discovery and informational reporting, not for executing untrusted payloads or commands.
  • [PROMPT_INJECTION]: Analysis of the skill instructions and reference materials found no evidence of prompt injection attempts, bypass markers, or instructions to ignore safety protocols.
  • [DATA_EXFILTRATION]: There are no patterns indicating access to sensitive local files (like SSH keys or AWS credentials) or unauthorized transmission of data to external domains.
  • [COMMAND_EXECUTION]: The skill focuses on providing design advice and reviewing code logic. It does not contain or suggest the execution of arbitrary shell commands or privilege escalation techniques.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 27, 2026, 09:35 AM