release
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its handling of untrusted external data:
- Ingestion points: The agent reads git commit history and merged Pull Request data to generate release notes and changelog entries (SKILL.md).
- Boundary markers: None; the skill does not specify delimiters or instructions to ignore potential commands embedded in commit messages or PR descriptions.
- Capability inventory: The skill can perform sensitive operations including
git push,npm publish, and executing the local script./scripts/deploy-docs.sh(SKILL.md). - Sanitization: There is no mention of sanitizing or validating the content retrieved from git history before it is interpolated into prompts or used in the release drafting process.
- [COMMAND_EXECUTION]: The skill relies on shell command execution to perform its primary functions:
- Executes
npm run registry:buildto perform build tasks. - Uses
git commit -amandgit pushto modify and upload repository content. - Executes a local shell script
./scripts/deploy-docs.shfor documentation deployment. - Runs
npm publishto distribute the package to the public registry.
Audit Metadata