changelog
Pass
Audited by Gen Agent Trust Hub on May 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local shell commands using
git logto retrieve commit history and the GitHub CLI (gh) to fetch pull request data and create releases. These operations are legitimate and necessary for the skill's documented purpose. - [PROMPT_INJECTION]: The skill processes untrusted text from external sources (git logs and PR descriptions), which presents a surface for indirect prompt injection attacks.
- Ingestion points: Commit messages retrieved via
git logand PR descriptions retrieved viagh pr listin SKILL.md (Phase 1). - Boundary markers: Absent. The instructions do not specify the use of delimiters or instructions to ignore potential commands embedded in the commit/PR data.
- Capability inventory: The skill has the ability to modify the
CHANGELOG.mdfile and executegh release createin SKILL.md (Phase 5). - Sanitization: No explicit sanitization, filtering, or escaping of the retrieved data is mentioned in the instructions.
- Mitigation: The risk is mitigated by mandatory human review and approval phases (Phase 2 and Phase 4) that occur before any final output is written or commands are executed.
Audit Metadata