kotlin-multiplatform-library-publishing
Pass
Audited by Gen Agent Trust Hub on Aug 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends initializing projects by cloning the official
Kotlin/multiplatform-library-templaterepository from GitHub. This is a well-known and trusted source for Kotlin development templates. - [DATA_EXFILTRATION]: The instructions reference local GPG signing configurations using
signing.secretKeyRingFilepointing to~/.gnupg/secring.gpg. This is a standard local development path for artifact signing, and the skill includes appropriate warnings against committing these secrets to version control. - [PROMPT_INJECTION]: The skill uses a
<PROJECT_NAME>placeholder that is interpolated directly into shell commands during the project initialization step. - Ingestion points: The
<PROJECT_NAME>variable provided by the user. - Boundary markers: None identified in the provided shell script snippets.
- Capability inventory: Shell command execution via
git clone,cd,rm, andgit init. - Sanitization: No explicit sanitization or escaping is provided for the project name before it is passed to the shell.
Audit Metadata