kotlin-multiplatform-ci-github-actions

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The CI workflow templates reference official GitHub Actions from well-known repositories, including actions/checkout, actions/setup-java, gradle/actions/setup-gradle, and actions/upload-artifact. These are standard components for CI/CD pipelines.
  • [COMMAND_EXECUTION]: The skill includes helper scripts (install-act.sh and run-ci-locally.sh) designed for local development. install-act.sh automates the installation of the 'act' utility via Homebrew, an established package manager. run-ci-locally.sh provides a way to execute the GitHub Actions workflows locally using Docker to save CI minutes.
  • [CREDENTIALS_UNSAFE]: The documentation and templates correctly handle sensitive data by advising the use of GitHub Secrets (e.g., GRADLE_ENCRYPTION_KEY) rather than hardcoding credentials in the repository.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 05:47 AM
Security Audit — agent-trust-hub — kotlin-multiplatform-ci-github-actions