kmp-delivery-lifecycle

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes shell commands to manage development workflows, including Git worktrees, Gradle builds, and GitHub CLI operations. These commands are standard for the intended task of managing a software delivery lifecycle.
  • Evidence:
  • Usage of git worktree add, git worktree remove, and git worktree prune for branch and environment management.
  • Execution of ./gradlew check and ./gradlew detekt for build verification and code quality auditing.
  • Usage of gh pr edit and gh issue edit for managing GitHub milestones and metadata.
  • Execution of local Python scripts within the skill environment: pr_visual_evidence.py and audit_project.py.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external data from GitHub issues and Pull Requests to verify delivery checklists. This represents a potential surface for indirect prompt injection if malicious instructions are embedded in these descriptions.
  • Evidence:
  • Ingestion points: GitHub issue descriptions and Pull Request bodies used for checklist verification (SKILL.md).
  • Boundary markers: No explicit delimitation or instructions to ignore embedded commands are present in the logic.
  • Capability inventory: Subprocess execution of Python scripts, Git commands, and GitHub CLI operations across various project source sets.
  • Sanitization: No specific sanitization or filtering of external issue/PR content is mentioned before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 10:23 AM
Security Audit — agent-trust-hub — kmp-delivery-lifecycle