kmp-xcframework-spm
Pass
Audited by Gen Agent Trust Hub on Aug 3, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references and utilizes well-known GitHub Actions (actions/checkout, actions/setup-java, gradle/actions/setup-gradle) within its automation workflows for building and releasing artifacts.
- [COMMAND_EXECUTION]: The instructions include standard development and build commands such as Gradle wrapper execution, archive compression (zip), and Swift package utility calls. These operations are restricted to local environment build tasks and repository management.
- [CREDENTIALS_UNSAFE]: The skill demonstrates best practices by using secure placeholders for sensitive information in CI/CD workflows, such as GitHub Secrets for environment variables and authentication tokens.
- [DATA_EXFILTRATION]: Network operations are directed towards well-known services (GitHub) for the legitimate purpose of publishing release artifacts and resolving package dependencies.
Audit Metadata