kmp-docs-site
Pass
Audited by Gen Agent Trust Hub on Aug 3, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill uses industry-standard tools (MkDocs Material, Dokka) and official GitHub Actions for its workflow. All procedures described align with the official documentation of the respective tools.
- [COMMAND_EXECUTION]: The skill contains standard shell commands for installing dependencies (
pip install mkdocs-material) and deploying documentation (mkdocs gh-deploy). These are legitimate actions for the intended purpose of building and publishing a website. - [EXTERNAL_DOWNLOADS]: Fetches
mkdocs-materialfrom the official Python Package Index (PyPI). This is a well-known and trusted package registry. - [DATA_EXFILTRATION]: The CI workflow (
.github/workflows/docs.yml) requestscontents: writepermissions. This is the minimum necessary permission required for an automated process to push built documentation to thegh-pagesbranch on GitHub. - [INDIRECT_PROMPT_INJECTION]: The skill includes a surface for processing local project data.
- Ingestion points: The
pymdownx.snippetsextension reads local source files from thedemo/directory into the documentation site. - Boundary markers: The skill specifically recommends using
START-docandEND-docregion comments to delimit extracted code. - Capability inventory: The skill uses
mkdocsfor building the site andgit(viagh-deploy) for publishing to the repository's hosting branch. - Sanitization: Relies on the standard markdown parsing and code-fencing capabilities of MkDocs and the
superfencesextension to safely render code snippets.
Audit Metadata