changelog

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses git and gh (GitHub CLI) to fetch repository information. These are standard developer tools and the GitHub CLI interacts with a well-known service. Commands utilized include git describe, git log, and gh pr list.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted data from git commit history. Ingestion points: Commit messages from git log in SKILL.md. Boundary markers: None provided to separate commit content from agent instructions. Capability inventory: Includes shell command execution and file system writes. Sanitization: None performed on commit subjects before output generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 12:16 PM
Security Audit — agent-trust-hub — changelog