release-audit
Pass
Audited by Gen Agent Trust Hub on Jul 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill follows a passive analysis pattern, performing read-only evaluations of repository manifest files (e.g.,
package.json,pyproject.toml,go.mod) to determine project scope and distribution channels. - [SAFE]: No evidence of malicious command execution, privilege escalation, or persistence mechanisms was found. The instructions focus on creating a scorecard based on static analysis findings.
- [SAFE]: The skill does not perform unauthorized network operations or exfiltrate data. While it instructs the agent to detect network surfaces like webhooks or listened ports, this is done for auditing purposes to report on security posture.
- [SAFE]: No obfuscation or prompt injection attempts were identified. The instructional language is professional and aligned with the stated purpose of release auditing.
Audit Metadata