kmp-project-docs-maintainer

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Several maintenance scripts (heal_project.py, generate_skills_lock.py, new_task.py) utilize subprocess.run to perform routine project tasks, such as executing local Python maintenance scripts and interacting with git. These operations are scoped to the project directory and are standard for developer productivity tools.
  • [EXTERNAL_DOWNLOADS]: The check_skills_lock.py script queries the GitHub API (api.github.com) to check for the latest releases of the kmp-agent-skills repository, facilitating project updates. Additionally, SKILL.md contains a recommendation for the third-party tool conorbronsdon/avoid-ai-writing for auditing prose.
  • [PERSISTENCE]: The heal_project.py script manages the installation and synchronization of a pre-commit git hook within the project's .git/hooks/ directory. This is a common automation practice to ensure code and documentation quality checks are run before commits.
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a documentation self-healing engine that reads and summarizes markdown files (.md) throughout the project. This ingestion of potentially untrusted project content creates a surface for indirect prompt injection.
  • Ingestion points: heal_docs.py recursively reads all markdown files in the docs/ directory to generate sitemaps and task indexes.
  • Boundary markers: The skill does not employ specific delimiters or "ignore instructions" tags when processing file content for document summaries.
  • Capability inventory: The skill possesses capabilities for filesystem writes, script permission modification, and shell command execution via subprocess.run.
  • Sanitization: Basic string escaping is performed for markdown table formatting, but the skill does not implement semantic validation or safety filtering for the documentation content it processes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 10:23 AM
Security Audit — agent-trust-hub — kmp-project-docs-maintainer