release-orchestrator

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill's Python scripts (scripts/preflight_checker.py, scripts/changelog_generator.py, and scripts/version_bumper.py) utilize subprocess.run to execute git commands for repository analysis, branch management, and metadata extraction. This is a standard and necessary function for release orchestration tasks.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the repository's git history, which could contain malicious instructions designed to influence the agent when it reviews the generated artifacts.
  • Ingestion points: scripts/changelog_generator.py and scripts/version_bumper.py ingest data directly from git log output, including user-controlled commit messages.
  • Boundary markers: Absent; the scripts do not wrap ingested commit content in delimiters or include instructions for the agent to ignore embedded commands within the log data.
  • Capability inventory: The skill has the capability to perform file system writes and execute repository operations via scripts/preflight_checker.py and scripts/version_bumper.py.
  • Sanitization: Absent; while the tools parse commits for conventional format, the description and body text are used directly in markdown output and version logic without filtering for prompt-like strings.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 07:27 AM
Security Audit — agent-trust-hub — release-orchestrator