kotlin-multiplatform-audit
Pass
Audited by Gen Agent Trust Hub on Aug 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
scripts/draft_issue.pyandscripts/governance_check.pyfiles utilizesubprocess.runto execute commands.draft_issue.pycalls the GitHub CLI (gh) for issue management, andgovernance_check.pyruns internal Python audit scripts. These are standard operations for the skill's purpose.- [DATA_EXFILTRATION]: Through thescripts/draft_issue.pyutility, the skill facilitates sending local project data (such as code snippets and audit findings) to external GitHub repositories. This is a user-initiated action intended for creating work items.- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface due to its core function of analyzing untrusted local project files. 1. Ingestion points: Files like*.ktand*.gradle.ktsare read usingPath.read_textinscripts/audit_project.pyandscripts/audit_skills_repo.py. 2. Boundary markers: The scripts do not use explicit delimiters or instructions to prevent the agent from potentially interpreting embedded text in the analyzed files as instructions. 3. Capability inventory: The skill can execute shell commands (subprocess.run), write output to files, and communicate with external repositories. 4. Sanitization: There is no evidence of content sanitization or filtering before project data is processed by the agent.
Audit Metadata