changelog
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill executes shell commands at load time to populate context with recent git history (
git log) and resolve configuration using a project-local script (yaml-helper.sh). These operations are consistent with the skill's purpose for project maintenance.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from git logs and external project files, creating a potential surface for indirect injection. \n - Ingestion points: Data is read from
git logoutput,production/sprints/, anddesign/gdd/as defined in Phase 2.\n - Boundary markers: The skill includes a 'Provenance check' section with explicit instructions for the agent to classify and validate the relevance of commit subjects before proceeding.\n
- Capability inventory: The skill utilizes
Bash,Write,Read,Glob, andGreptools to gather data and save the final changelog.\n - Sanitization: Instructions in Phase 5 and the 'Guidelines' section direct the agent to filter out technical jargon, code references, and internal names for the player-facing version.
Audit Metadata