omcustom-release-notes
Warn
Audited by Gen Agent Trust Hub on May 15, 2026
Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill includes explicit instructions in the 'Permission Mode' section to use 'mode: "bypassPermissions"' when spawning sub-agents. This is a deliberate attempt to override platform-level security defaults that require user consent for actions or edits, allowing the agent to perform operations without user review.
- [COMMAND_EXECUTION]: Phase 5 of the skill implements dynamic code execution by generating a Python script on-the-fly and executing it via a shell heredoc ('python3
- ... <<'PY''). This script directly modifies the 'CHANGELOG.md' file based on interpolated variables.
- [PROMPT_INJECTION]: The skill demonstrates an indirect prompt injection attack surface by ingesting untrusted data from external sources and using it in subsequent commands.
- Ingestion points: The skill reads commit messages via 'git log' and issue metadata (titles, labels) via 'gh issue list'.
- Boundary markers: No specific delimiters or safety instructions are provided to the agent to prevent it from obeying instructions that might be embedded within commit messages or issue titles.
- Capability inventory: The skill possesses the capability to write to the local filesystem ('CHANGELOG.md') and execute shell commands through the 'gh' CLI ('gh release create').
- Sanitization: While the Python script escapes some variables, the primary content used to generate release notes is taken directly from the repository history and issues and interpolated into command arguments without sanitization.
Audit Metadata