kmp-build

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides standard project templates and build instructions for Kotlin Multiplatform development.
  • [PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection by processing external project data and executing shell commands. This is a functional requirement for its purpose as a build tool.
  • Ingestion points: Project configuration files such as shared/build.gradle.kts and iosApp/Info.plist are read by the agent to facilitate the build process.
  • Boundary markers: The skill does not define specific delimiters to separate untrusted project content from instructions.
  • Capability inventory: The agent is instructed to execute build commands like ./gradlew and xcodebuild based on project content.
  • Sanitization: There is no explicit sanitization of data extracted from project files before it is used in shell command templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 12:16 AM