kmp-delivery-lifecycle
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes shell commands to manage development workflows, including Git worktrees, Gradle builds, and GitHub CLI operations. These commands are standard for the intended task of managing a software delivery lifecycle.
- Evidence:
- Usage of
git worktree add,git worktree remove, andgit worktree prunefor branch and environment management. - Execution of
./gradlew checkand./gradlew detektfor build verification and code quality auditing. - Usage of
gh pr editandgh issue editfor managing GitHub milestones and metadata. - Execution of local Python scripts within the skill environment:
pr_visual_evidence.pyandaudit_project.py. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external data from GitHub issues and Pull Requests to verify delivery checklists. This represents a potential surface for indirect prompt injection if malicious instructions are embedded in these descriptions.
- Evidence:
- Ingestion points: GitHub issue descriptions and Pull Request bodies used for checklist verification (SKILL.md).
- Boundary markers: No explicit delimitation or instructions to ignore embedded commands are present in the logic.
- Capability inventory: Subprocess execution of Python scripts, Git commands, and GitHub CLI operations across various project source sets.
- Sanitization: No specific sanitization or filtering of external issue/PR content is mentioned before processing.
Audit Metadata