release
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests content from CHANGELOG.md to generate release notes, creating a potential surface for indirect prompt injection. • Ingestion points: CHANGELOG.md (Step 3). • Boundary markers: None specified. • Capability inventory: The skill uses git, npm, and npx. • Sanitization: No specific sanitization mentioned for changelog content.
- [COMMAND_EXECUTION]: The skill executes standard shell commands to manage the release lifecycle. • Evidence: pnpm sync:versions, pnpm build, pnpm release, git tag, git push, and npm view.
- [EXTERNAL_DOWNLOADS]: The skill performs network operations to verify published packages and fetch remote skill extensions from vendor-controlled sources. • Evidence: Fetches packages from the npm registry using npx for verification. • Evidence: Downloads skills from the vendor's GitHub repository using npx skills add crissmoldovan/agent-communications.
Audit Metadata