release-readiness-review

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a static template for generating release readiness reports. It does not include any scripts, executable code, or remote dependencies.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines an attack surface by ingesting external data through configuration fields like release_name and release_version. However, the capability inventory for this skill is empty (no file-system access, network operations, or shell execution), which prevents any potentially injected instructions from being executed.
  • Ingestion points: release_version, release_name, and release_date configuration fields in SKILL.md.
  • Boundary markers: Absent.
  • Capability inventory: None detected; the skill contains no scripts or subprocess calls.
  • Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 10:18 PM
Security Audit — agent-trust-hub — release-readiness-review