finding-changelogs

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes an attack surface for indirect prompt injection by design, as it instructs the agent to ingest and process content from untrusted external sources like RSS feeds, raw markdown files (CHANGELOG.md), and scraped web pages.
  • Ingestion points: Third-party changelog URLs, .well-known manifest files, and repository-level markdown files (e.g., CHANGELOG.md, HISTORY.md) are fetched into the agent's context.
  • Boundary markers: While the skill provides heuristics to verify content validity (e.g., checking for semver patterns), it does not explicitly define structural delimiters to prevent the agent from following instructions embedded within the ingested changelogs.
  • Capability inventory: The agent has access to tools for web fetching (WebFetch), catalog searching, and database management (manage_source, manage_product, manage_org).
  • Sanitization: The skill mentions internal adapter logic that strips provider-specific noise (like Fern MDX attributes) and performs structural evaluation of the pages.
  • [EXTERNAL_DOWNLOADS]: The skill's primary function involves discovering and retrieving data from external entities, including GitHub repositories and arbitrary third-party domains. It includes a specific priority list for discovery, ranging from standard well-known files to heuristic scraping.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 11:02 AM