kmp-build
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides standard project templates and build instructions for Kotlin Multiplatform development.
- [PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection by processing external project data and executing shell commands. This is a functional requirement for its purpose as a build tool.
- Ingestion points: Project configuration files such as shared/build.gradle.kts and iosApp/Info.plist are read by the agent to facilitate the build process.
- Boundary markers: The skill does not define specific delimiters to separate untrusted project content from instructions.
- Capability inventory: The agent is instructed to execute build commands like ./gradlew and xcodebuild based on project content.
- Sanitization: There is no explicit sanitization of data extracted from project files before it is used in shell command templates.
Audit Metadata