kmp-docs-site

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill uses industry-standard tools (MkDocs Material, Dokka) and official GitHub Actions for its workflow. All procedures described align with the official documentation of the respective tools.
  • [COMMAND_EXECUTION]: The skill contains standard shell commands for installing dependencies (pip install mkdocs-material) and deploying documentation (mkdocs gh-deploy). These are legitimate actions for the intended purpose of building and publishing a website.
  • [EXTERNAL_DOWNLOADS]: Fetches mkdocs-material from the official Python Package Index (PyPI). This is a well-known and trusted package registry.
  • [DATA_EXFILTRATION]: The CI workflow (.github/workflows/docs.yml) requests contents: write permissions. This is the minimum necessary permission required for an automated process to push built documentation to the gh-pages branch on GitHub.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes a surface for processing local project data.
  • Ingestion points: The pymdownx.snippets extension reads local source files from the demo/ directory into the documentation site.
  • Boundary markers: The skill specifically recommends using START-doc and END-doc region comments to delimit extracted code.
  • Capability inventory: The skill uses mkdocs for building the site and git (via gh-deploy) for publishing to the repository's hosting branch.
  • Sanitization: Relies on the standard markdown parsing and code-fencing capabilities of MkDocs and the superfences extension to safely render code snippets.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 05:49 AM
Security Audit — agent-trust-hub — kmp-docs-site