kotlin-multiplatform-release
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill promotes secure credential management by instructing users to store sensitive information like Maven Central tokens and GPG signing keys in environment variables (ORG_GRADLE_PROJECT_*) or secrets managers (e.g., GitHub Secrets, Doppler), rather than hardcoding them in the project.
- [SAFE]: The release workflow uses established and well-known tools, including the com.vanniktech.maven.publish Gradle plugin and git-cliff for changelog generation, which are standard in the Kotlin ecosystem.
- [SAFE]: The provided shell script for automating releases (publish.sh) follows defensive programming practices, such as using set -euo pipefail and deriving version numbers through controlled logic, minimizing the risk of unintended side effects or command injection.
Audit Metadata