demo-release-packager

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill contains only instructional text and configuration files. No executable scripts, binaries, or shell commands are included.
  • [DATA_EXFILTRATION]: The skill incorporates defensive logic by explicitly instructing the agent to exclude sensitive files (e.g., HAR dumps, console logs, trace files) and data (e.g., secrets, tokens, PII) from generated bundles.
  • [INDIRECT_PROMPT_INJECTION]: The skill logic processes external artifacts such as media files and evidence links. While these enter the agent's context, the skill's purpose is limited to organization and documentation, and it lacks the computational capabilities (like network access or code execution) required for high-risk exploitation of injected instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 12:00 PM
Security Audit — agent-trust-hub — demo-release-packager