patch-notes

Warn

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: MEDIUMDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes the ! command syntax to execute a shell command automatically when the skill is loaded. The command bash "${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh" resolve_config --keys automation uses path traversal to execute a script located outside of the skill's specific directory.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes various external and potentially untrusted data sources to generate player-facing patch notes.
  • Ingestion points: The skill ingests text from git log, production/releases/, docs/CHANGELOG.md, production/sprints/, design/balance/, and QA bug records.
  • Boundary markers: There are no explicit delimiters or boundary markers used to separate untrusted ingested data from the skill's instructions.
  • Capability inventory: The skill has the capability to write to the file system (Write) and execute shell commands (Bash).
  • Sanitization: The skill does not implement sanitization, filtering, or escaping for the data read from logs or external files before it is processed by the model.
  • [COMMAND_EXECUTION]: The skill relies on shell commands for repository analysis (git log) and project configuration resolution via a custom bash hook.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 30, 2026, 06:52 PM
Security Audit — agent-trust-hub — patch-notes