kotlin-multiplatform-feature-scaffold
Pass
Audited by Gen Agent Trust Hub on Aug 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill clones the project baseline from the official Kotlin wizard repository (github.com/Kotlin/kmp-wizard). This is a recognized and official source for Kotlin Multiplatform project templates.
- [COMMAND_EXECUTION]: Customizes the project using standard shell commands such as git clone, mv, and sed. These commands are localized to the project environment and are used to customize package names and directory structures based on user input.
- [PROMPT_INJECTION]: The skill exposes an indirect prompt injection surface by interpolating user-provided inputs like PROJECT_NAME and GROUP_ID into file templates and shell commands. Ingestion points: User-provided metadata during the Step 1 phase (SKILL.md). Boundary markers: None. Capability inventory: File system modifications and local command execution. Sanitization: None observed in the skill instructions.
- [SAFE]: No malicious patterns, such as data exfiltration to unauthorized domains, obfuscation techniques, or persistence mechanisms, were identified in the skill.
Audit Metadata