build-release-engineer

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses dynamic context injection (the ! command syntax) to read project configuration files like .production-grade.yaml and .forgewright/codebase-context.md to initialize the agent's environment. It also provides shell and PowerShell scripts for executing platform-specific build tools such as xcodebuild, gradlew, and Unity's command-line interface.
  • [REMOTE_CODE_EXECUTION]: The skill documents a HotfixManager implementation in C# that allows a game to download and apply updates at runtime. This functionality is a standard part of game maintenance and is provided as a reference implementation for users.
  • [PROMPT_INJECTION]: The skill architecture is susceptible to indirect prompt injection through the ingestion of repository files and workflow configurations.
  • Ingestion points: Files located at .forgewright/project-profile.json and .github/workflows/ are read to determine project state.
  • Boundary markers: No explicit delimiter-based sanitization is implemented in the provided code snippets.
  • Capability inventory: The skill includes extensive capabilities for file system modification, command execution, and network communication via the generated build and release scripts.
  • Sanitization: Security is maintained through standard cryptographic hash verification (SHA256) within the provided hotfix delivery template.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 08:30 AM
Security Audit — agent-trust-hub — build-release-engineer