kmp-flavor-environment
Pass
Audited by Gen Agent Trust Hub on Aug 3, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill follows mobile development best practices by instructing users to store sensitive keys in a 'local.properties' file and ensuring it is added to '.gitignore' to prevent accidental credential leakage to source control.
- [SAFE]: Configuration snippets for Gradle and Xcode are standard for the Kotlin Multiplatform ecosystem and do not contain any malicious commands, obfuscation, or unauthorized network operations.
- [SAFE]: The recommendation to use environment variables for CI (GitHub Actions) secret injection is a secure and standard method for managing production credentials.
Audit Metadata