buildkite-agent-release

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the GitHub command-line interface (gh) to list repository releases, call the GitHub API for note generation, and automate PR creation.- [EXTERNAL_DOWNLOADS]: The skill interacts with GitHub, which is a well-known and trusted service, to manage repository state and metadata.- [INDIRECT_PROMPT_INJECTION]: By processing PR titles and labels to generate release notes, the skill possesses an attack surface where external metadata could influence the generated content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 01:58 AM
Security Audit — agent-trust-hub — buildkite-agent-release