kotlin-multiplatform-audit

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The scripts/draft_issue.py and scripts/governance_check.py files utilize subprocess.run to execute commands. draft_issue.py calls the GitHub CLI (gh) for issue management, and governance_check.py runs internal Python audit scripts. These are standard operations for the skill's purpose.- [DATA_EXFILTRATION]: Through the scripts/draft_issue.py utility, the skill facilitates sending local project data (such as code snippets and audit findings) to external GitHub repositories. This is a user-initiated action intended for creating work items.- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface due to its core function of analyzing untrusted local project files. 1. Ingestion points: Files like *.kt and *.gradle.kts are read using Path.read_text in scripts/audit_project.py and scripts/audit_skills_repo.py. 2. Boundary markers: The scripts do not use explicit delimiters or instructions to prevent the agent from potentially interpreting embedded text in the analyzed files as instructions. 3. Capability inventory: The skill can execute shell commands (subprocess.run), write output to files, and communicate with external repositories. 4. Sanitization: There is no evidence of content sanitization or filtering before project data is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 05:47 AM
Security Audit — agent-trust-hub — kotlin-multiplatform-audit