changelog
Pass
Audited by Gen Agent Trust Hub on Jul 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides guidelines for documenting software changes following industry standards. All referenced resources, including those from the AsiaOstrich organization, are legitimate for the skill's purpose.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from
git logto generate changelog entries. Although this is external data that could contain injection attempts, the risk is limited by the skill's focus on summarizing history for human-readable files. (Ingestion: git log command in SKILL.md; Boundary markers: None explicitly mentioned in prompt template; Capabilities: Write tool used to update CHANGELOG.md; Sanitization: Agent-driven summarization of commit messages).
Audit Metadata