kotlin-multiplatform-library-publishing

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends initializing projects by cloning the official Kotlin/multiplatform-library-template repository from GitHub. This is a well-known and trusted source for Kotlin development templates.
  • [DATA_EXFILTRATION]: The instructions reference local GPG signing configurations using signing.secretKeyRingFile pointing to ~/.gnupg/secring.gpg. This is a standard local development path for artifact signing, and the skill includes appropriate warnings against committing these secrets to version control.
  • [PROMPT_INJECTION]: The skill uses a <PROJECT_NAME> placeholder that is interpolated directly into shell commands during the project initialization step.
  • Ingestion points: The <PROJECT_NAME> variable provided by the user.
  • Boundary markers: None identified in the provided shell script snippets.
  • Capability inventory: Shell command execution via git clone, cd, rm, and git init.
  • Sanitization: No explicit sanitization or escaping is provided for the project name before it is passed to the shell.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 05:47 AM
Security Audit — agent-trust-hub — kotlin-multiplatform-library-publishing