kmp-feature-scaffold
Pass
Audited by Gen Agent Trust Hub on Aug 8, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill instructs the agent to download the baseline project template from the official Kotlin GitHub repository (
Kotlin/kmp-wizard). This is a trusted source for Kotlin Multiplatform templates. - [INDIRECT_PROMPT_INJECTION]: The skill defines a process where user-provided inputs, such as project names and group IDs, are interpolated into generated source code and build configuration files. While this represents a theoretical attack surface for code injection, it is the primary and intended function of a scaffolding tool.
- [COMMAND_EXECUTION]: The skill includes a local Python script (
scripts/validate_module_graph.py) to verify the integrity of the generated project structure. The script performs standard file system checks and does not exhibit malicious patterns. - [COMMAND_EXECUTION]: The instructions utilize standard shell utilities such as
gitandsedto automate the configuration of the cloned project. These commands are used for legitimate project initialization tasks like updating package names and versioning strings.
Audit Metadata