release-readiness-review
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a static template for generating release readiness reports. It does not include any scripts, executable code, or remote dependencies.
- [INDIRECT_PROMPT_INJECTION]: The skill defines an attack surface by ingesting external data through configuration fields like
release_nameandrelease_version. However, the capability inventory for this skill is empty (no file-system access, network operations, or shell execution), which prevents any potentially injected instructions from being executed. - Ingestion points:
release_version,release_name, andrelease_dateconfiguration fields inSKILL.md. - Boundary markers: Absent.
- Capability inventory: None detected; the skill contains no scripts or subprocess calls.
- Sanitization: Absent.
Audit Metadata