kmp-feature-scaffold

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructs the agent to download the baseline project template from the official Kotlin GitHub repository (Kotlin/kmp-wizard). This is a trusted source for Kotlin Multiplatform templates.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a process where user-provided inputs, such as project names and group IDs, are interpolated into generated source code and build configuration files. While this represents a theoretical attack surface for code injection, it is the primary and intended function of a scaffolding tool.
  • [COMMAND_EXECUTION]: The skill includes a local Python script (scripts/validate_module_graph.py) to verify the integrity of the generated project structure. The script performs standard file system checks and does not exhibit malicious patterns.
  • [COMMAND_EXECUTION]: The instructions utilize standard shell utilities such as git and sed to automate the configuration of the cloned project. These commands are used for legitimate project initialization tasks like updating package names and versioning strings.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 04:14 AM
Security Audit — agent-trust-hub — kmp-feature-scaffold