demo-release-packager
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill contains only instructional text and configuration files. No executable scripts, binaries, or shell commands are included.
- [DATA_EXFILTRATION]: The skill incorporates defensive logic by explicitly instructing the agent to exclude sensitive files (e.g., HAR dumps, console logs, trace files) and data (e.g., secrets, tokens, PII) from generated bundles.
- [INDIRECT_PROMPT_INJECTION]: The skill logic processes external artifacts such as media files and evidence links. While these enter the agent's context, the skill's purpose is limited to organization and documentation, and it lacks the computational capabilities (like network access or code execution) required for high-risk exploitation of injected instructions.
Audit Metadata