kotlin-toolchain-plugin-authoring

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is purely instructional, providing templates and architectural guidance for extending the Kotlin Toolchain. The practices described—such as file system interactions within task actions and the use of environment variables for configuration—are standard for build-time tooling and occur within the expected context of a build plugin.
  • [COMMAND_EXECUTION]: The documentation describes how the build system executes @TaskAction functions and supports CLI commands (./kotlin do <command>). These are core functionalities of the Amper build system and the skill teaches their legitimate use for build automation and workflows.
  • [DATA_EXFILTRATION]: No evidence of unauthorized data access or exfiltration. The skill uses declared @Input and @Output paths to manage file dependencies between build tasks, which is the recommended practice for build-time data flow.
  • [EXTERNAL_DOWNLOADS]: The skill references official documentation at kotlin-toolchain.org, which is an established domain for the project. No downloads from untrusted or suspicious sources were identified.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 01:45 PM
Security Audit — agent-trust-hub — kotlin-toolchain-plugin-authoring