kotlin-multiplatform-release

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill promotes secure credential management by instructing users to store sensitive information like Maven Central tokens and GPG signing keys in environment variables (ORG_GRADLE_PROJECT_*) or secrets managers (e.g., GitHub Secrets, Doppler), rather than hardcoding them in the project.
  • [SAFE]: The release workflow uses established and well-known tools, including the com.vanniktech.maven.publish Gradle plugin and git-cliff for changelog generation, which are standard in the Kotlin ecosystem.
  • [SAFE]: The provided shell script for automating releases (publish.sh) follows defensive programming practices, such as using set -euo pipefail and deriving version numbers through controlled logic, minimizing the risk of unintended side effects or command injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 03:15 AM
Security Audit — agent-trust-hub — kotlin-multiplatform-release