release-manager
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external sources that could contain malicious instructions designed to influence the behavior of the AI agent.
- Ingestion points:
changelog_generator.pyandversion_bumper.pyread git log data from stdin or input files;release_planner.pyreads JSON-formatted release plans. - Boundary markers: The scripts do not implement explicit delimiters or instructions to the agent to treat the ingested commit messages or feature descriptions as untrusted content.
- Capability inventory: All scripts utilize the Python standard library to read from and write to the local file system (e.g.,
open(args.input),open(args.output)). - Sanitization: No filtering or sanitization is performed on the descriptive text within commit messages or release plans to identify or block embedded prompt injection patterns.
Audit Metadata