newsletter
Pass
Audited by Gen Agent Trust Hub on May 11, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources including GitHub pull request descriptions, commit messages, and local project files to generate newsletter content.
- Ingestion points: Data enters the agent context through the outputs of
gh pr view,gh pr diff,git log, andgit diffcommands, as well as via direct reading of local markdown and codebase files (e.g.,SKILL.mdPhase 1). - Boundary markers: There are no explicit instructions or delimiters defined to separate untrusted content from the system instructions or to warn the agent to ignore embedded commands within the ingested text.
- Capability inventory: The skill has capabilities to read local files, execute shell commands (
gh,git), and write files to the localemails/directory (e.g.,SKILL.mdPhase 5). - Sanitization: No explicit sanitization or filtering logic is documented for the data ingested from PRs or logs before it is used in the writing phase.
- [COMMAND_EXECUTION]: The skill uses local command-line interfaces to gather necessary data for its tasks.
- Evidence: It explicitly calls
gh pr view,gh pr diff,git diff, andgit logto extract information about code changes and project history (e.g.,SKILL.mdPhase 1). This is standard behavior for its intended use case.
Audit Metadata