release-notes
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from Git commit messages and Pull Request descriptions as described in
SKILL.md. An attacker could embed malicious instructions within these sources to influence the agent's output or actions. The instruction set lacks explicit boundary markers or delimiters to separate data from instructions. Furthermore, the skill has the capability to trigger 'authorized release workflows' based on the analyzed content, which represents a potential capability for automated actions based on poisoned inputs. No sanitization or filtering logic is provided for the external content.
Audit Metadata