changelog-from-diff

Pass

Audited by Gen Agent Trust Hub on Jul 7, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted external data in the form of git diffs and commits, which serves as an ingestion point for indirect prompt injection. Malicious actors could embed instructions within code comments to influence the agent's summary or behavior. There are no boundary markers or sanitization steps defined in the prompt to mitigate this risk.
  • [NO_CODE]: The skill consists entirely of instructional markdown and does not include any scripts, configuration files, or executable binaries.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 7, 2026, 05:08 PM
Security Audit — agent-trust-hub — changelog-from-diff