release-manager

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external sources that could contain malicious instructions designed to influence the behavior of the AI agent.
  • Ingestion points: changelog_generator.py and version_bumper.py read git log data from stdin or input files; release_planner.py reads JSON-formatted release plans.
  • Boundary markers: The scripts do not implement explicit delimiters or instructions to the agent to treat the ingested commit messages or feature descriptions as untrusted content.
  • Capability inventory: All scripts utilize the Python standard library to read from and write to the local file system (e.g., open(args.input), open(args.output)).
  • Sanitization: No filtering or sanitization is performed on the descriptive text within commit messages or release plans to identify or block embedded prompt injection patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 08:34 PM
Security Audit — agent-trust-hub — release-manager