kmp-library-publishing
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends the use of the
com.vanniktech.maven.publishGradle plugin and references an official library template from the Kotlin organization on GitHub. These are standard, well-recognized resources within the Kotlin development ecosystem. - [COMMAND_EXECUTION]: The instructions include standard shell commands for GPG key management (e.g.,
gpg --gen-key) and Gradle tasks (e.g.,./gradlew publishAllPublicationsToMavenCentralRepository). These operations are essential for the stated purpose of library distribution and do not exhibit malicious patterns. - [CREDENTIALS_UNSAFE]: The skill addresses the handling of sensitive credentials, such as GPG keys and Sonatype tokens. It demonstrates a security-conscious approach by explicitly advising against committing secrets to version control and recommending the use of environment variables and secure secret stores like GitHub Actions Secrets.
Audit Metadata