release

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests content from CHANGELOG.md to generate release notes, creating a potential surface for indirect prompt injection. • Ingestion points: CHANGELOG.md (Step 3). • Boundary markers: None specified. • Capability inventory: The skill uses git, npm, and npx. • Sanitization: No specific sanitization mentioned for changelog content.
  • [COMMAND_EXECUTION]: The skill executes standard shell commands to manage the release lifecycle. • Evidence: pnpm sync:versions, pnpm build, pnpm release, git tag, git push, and npm view.
  • [EXTERNAL_DOWNLOADS]: The skill performs network operations to verify published packages and fetch remote skill extensions from vendor-controlled sources. • Evidence: Fetches packages from the npm registry using npx for verification. • Evidence: Downloads skills from the vendor's GitHub repository using npx skills add crissmoldovan/agent-communications.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 11:18 PM
Security Audit — agent-trust-hub — release