kmp-audit
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Several scripts within the skill utilize
subprocess.runto perform their tasks.governance_check.pyorchestrates the audit by executing peer scripts likeaudit_project.pyandaudit_skills_repo.py.draft_issue.pyinvokes the standard GitHub CLI (gh) to create issues or questions based on audit findings. These executions are legitimate given the skill's purpose as a project auditor and workflow helper. - [INDIRECT_PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection because it is designed to ingest and analyze untrusted external data (Kotlin source code, Gradle configurations, and Markdown documentation) from the projects it audits.
- Ingestion points: Files are read by
audit_skills_repo.py,classify_declarations.py, andaudit_project.py(viagovernance_check.py). - Boundary markers: The scripts read file content directly without specific delimiters or warnings to the agent regarding potential embedded instructions.
- Capability inventory: The skill has the ability to write to the file system (via
draft_issue.pycreating temporary files) and interact with external APIs (via theghCLI for issue creation). - Sanitization: While
draft_issue.pycorrectly usesshlex.quoteto sanitize shell command arguments, the actual content of the generated issues is derived directly from the analyzed files without additional sanitization, which could lead to markdown-based injection in the final issue report. - [EXTERNAL_DOWNLOADS]: The documentation in
references/governance-ci-enforcement.mdprovides instructions for integrating the audit into CI/CD pipelines by referencing a reusable GitHub workflow hosted in the author's own repository (ronjunevaldoz/kmp-agent-skills). This is a standard practice for managing shared CI workflows and originates from the recognized vendor/author.
Audit Metadata