kotlin-toolchain-plugin-authoring
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is purely instructional, providing templates and architectural guidance for extending the Kotlin Toolchain. The practices described—such as file system interactions within task actions and the use of environment variables for configuration—are standard for build-time tooling and occur within the expected context of a build plugin.
- [COMMAND_EXECUTION]: The documentation describes how the build system executes
@TaskActionfunctions and supports CLI commands (./kotlin do <command>). These are core functionalities of the Amper build system and the skill teaches their legitimate use for build automation and workflows. - [DATA_EXFILTRATION]: No evidence of unauthorized data access or exfiltration. The skill uses declared
@Inputand@Outputpaths to manage file dependencies between build tasks, which is the recommended practice for build-time data flow. - [EXTERNAL_DOWNLOADS]: The skill references official documentation at
kotlin-toolchain.org, which is an established domain for the project. No downloads from untrusted or suspicious sources were identified.
Audit Metadata