release-orchestrator
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill's Python scripts (scripts/preflight_checker.py, scripts/changelog_generator.py, and scripts/version_bumper.py) utilize subprocess.run to execute git commands for repository analysis, branch management, and metadata extraction. This is a standard and necessary function for release orchestration tasks.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the repository's git history, which could contain malicious instructions designed to influence the agent when it reviews the generated artifacts.
- Ingestion points: scripts/changelog_generator.py and scripts/version_bumper.py ingest data directly from git log output, including user-controlled commit messages.
- Boundary markers: Absent; the scripts do not wrap ingested commit content in delimiters or include instructions for the agent to ignore embedded commands within the log data.
- Capability inventory: The skill has the capability to perform file system writes and execute repository operations via scripts/preflight_checker.py and scripts/version_bumper.py.
- Sanitization: Absent; while the tools parse commits for conventional format, the description and body text are used directly in markdown output and version logic without filtering for prompt-like strings.
Audit Metadata