kotlin-multiplatform-lessons

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a bundled Python script, create_lesson.py, to generate and manage lesson files. The script uses standard libraries for command-line argument parsing and file system operations, incorporating a restricted slugification process to prevent path traversal vulnerabilities when generating filenames.
  • [DATA_EXFILTRATION]: Instructions within the skill prompt the agent to proactively draft GitHub issues for the ronjunevaldoz/kmm-agent-skills repository when high-severity guidance errors are found. While the final submission requires an explicit 'yes' from the user, the agent is directed to collect project context (the 'evidence' field) for this external draft.
  • [PROMPT_INJECTION]: The skill includes instructions for high autonomy, specifically telling the agent to 'Trigger automatically (no user prompt needed)' and 'Trigger it proactively' following certain development milestones. While this bypasses standard request-response loops for this specific documentation task, it is limited to the skill's stated purpose of knowledge capture.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection by ingesting untrusted data from the local project environment.
  • Ingestion points: The agent reads project-specific file paths, line-level code excerpts, and error messages to populate the 'Evidence' and 'What broke' fields in SKILL.md.
  • Boundary markers: There are no explicit boundary markers or instructions to ignore embedded directives in the ingested 'evidence' content.
  • Capability inventory: The skill can execute local Python scripts for file writing and suggests the use of the /report-skill-issue tool for GitHub submissions as noted in SKILL.md.
  • Sanitization: The create_lesson.py script sanitizes filenames via slugification but does not perform content sanitization or escaping on the ingested project data written to the lesson body.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 03:15 AM
Security Audit — agent-trust-hub — kotlin-multiplatform-lessons