kmp-expert

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes user-supplied project descriptions and external specification files to infer feature sets, generate delivery plans, and architecture tasks.
  • Ingestion points: Untrusted data enters the agent context through the $ARGUMENTS variable and referenced local project specification files.
  • Boundary markers: The skill defines a stack-scope guard and a 'Freshness Rule' to prioritize local repository content, but lacks explicit boundary markers or instructions to disregard potential instructions embedded within the ingested specification files.
  • Capability inventory: The skill has capabilities to write files (PLAN.md, docs/architecture.md), execute local maintenance scripts, and delegate to other domain-specific skills with broader system and network access.
  • Sanitization: There is no documented sanitization or validation of the ingested text before it is used to drive the agent's planning and implementation logic.
  • [EXTERNAL_DOWNLOADS]: The skill automates the retrieval of project templates and recommends external library dependencies.
  • Trusted Templates: Scaffolding steps involve cloning from github.com/Kotlin/kmp-wizard and github.com/Kotlin/multiplatform-library-template. These are official repositories from a well-known technology organization.
  • Vendor Resources: The skill recommends various libraries authored by ronjunevaldoz (e.g., shadcn-compose, heroicons-outline, tailwind-compose), which are consistent with the identified author context and represent standard vendor functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 10:23 AM
Security Audit — agent-trust-hub — kmp-expert