kotlin-tooling-cocoapods-spm-migration
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes a suite of standard shell commands (
grep,find,sed,rm) and platform-specific build tools (xcodebuild,./gradlew,pod) to perform project introspection, configuration updates, and build verification. These operations, including the removal of CocoaPods artifacts and modification of project settings, are necessary steps for the migration process. - [EXTERNAL_DOWNLOADS]: The skill configures project dependencies using the Swift Package Manager (SPM) integration in Gradle. It references several external repositories for popular development libraries, including those provided by well-known organizations like Google, Firebase, and Apple. These downloads are performed through standard dependency management channels.
- [DYNAMIC_EXECUTION]: A complex shell command in the migration instructions uses an inline Python script to parse JSON output from Xcode. This is used as a utility to programmatically identify valid project schemes and automate the discovery of integration commands within the local development environment.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted local data from project configuration files to guide its migration logic.
- Ingestion points: Reads contents from
build.gradle.kts,gradle/libs.versions.toml,Podfile, andproject.pbxproj(Xcode project files). - Boundary markers: The workflow includes multiple user verification points and advises on manual checks for build success.
- Capability inventory: The skill employs file system modifications, build command execution, and code transformation capabilities across its instructional phases.
- Sanitization: Uses specific regex patterns to target and transform
cocoapods.*imports to the newswiftPMImport.*namespace while preserving bundled library imports.
Audit Metadata