prepare-providers-documentation
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external sources to automate core release activities, creating a potential vulnerability surface.
- Ingestion points: The skill fetches PR titles, descriptions, and code diffs using
gh pr viewandgh pr diffin Phase 3 of SKILL.md. - Boundary markers: Absent. The prompt instructions for sub-agents do not use robust delimiters or isolation instructions for the untrusted PR data, which could allow malicious content in a PR to influence the agent's behavior.
- Capability inventory: The skill has extensive capabilities, including shell command execution (
breeze,git,gh,prek), modifying sensitive configuration files (provider.yaml), and writing to changelogs. - Sanitization: Absent. There is no evidence of filtering or validation of external PR content before it is processed by the LLM sub-agents.
- [DYNAMIC_EXECUTION]: The skill uses a shell heredoc to dynamically generate and execute a Python script (SKILL.md, Incremental Phase 2). While the script's logic is statically defined within the skill itself, this pattern involves the runtime generation and execution of code.
Audit Metadata