kmp-library-publishing

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends the use of the com.vanniktech.maven.publish Gradle plugin and references an official library template from the Kotlin organization on GitHub. These are standard, well-recognized resources within the Kotlin development ecosystem.
  • [COMMAND_EXECUTION]: The instructions include standard shell commands for GPG key management (e.g., gpg --gen-key) and Gradle tasks (e.g., ./gradlew publishAllPublicationsToMavenCentralRepository). These operations are essential for the stated purpose of library distribution and do not exhibit malicious patterns.
  • [CREDENTIALS_UNSAFE]: The skill addresses the handling of sensitive credentials, such as GPG keys and Sonatype tokens. It demonstrates a security-conscious approach by explicitly advising against committing secrets to version control and recommending the use of environment variables and secure secret stores like GitHub Actions Secrets.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 11:34 PM
Security Audit — agent-trust-hub — kmp-library-publishing