skills/cyrusagents/cyrus/release/Gen Agent Trust Hub

release

Pass

Audited by Gen Agent Trust Hub on Apr 26, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill implements a logical and transparent release workflow using standard development tools such as pnpm, git, and the GitHub CLI (gh).
  • [COMMAND_EXECUTION]: The skill utilizes shell commands to manage dependencies, build workspace packages, and publish them to the public npm registry according to a specific dependency order.
  • [PROMPT_INJECTION]: The skill features an indirect prompt injection surface through the ingestion of local changelog files to generate release metadata. This operation is considered safe as it is essential to the skill's utility and occurs within a developer-controlled environment. Ingestion points: CHANGELOG.md and CHANGELOG.internal.md. Boundary markers: None (direct interpolation). Capability inventory: git, pnpm, and gh. Sanitization: None.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 26, 2026, 06:05 PM
Security Audit — agent-trust-hub — release