kmp-legal-docs

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes a Python script (detect_data_collection.py) designed to scan project source code for data collection markers like analytics SDKs and permission declarations. The script performs read-only regex searches on local files and outputs findings to the console for the user or agent to review.
  • [EXTERNAL_DOWNLOADS]: Instructions reference official documentation from Google and Apple for platform-specific privacy requirements. These links point to well-known, trusted developer support domains.
  • [SAFE]: The skill follows security and legal best practices for mobile applications, such as advising against hardcoding legal text in favor of remote URLs and implementing a version-pinned consent gate to ensure users re-accept policies after material changes.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 04:15 AM
Security Audit — agent-trust-hub — kmp-legal-docs