patch-notes
Warn
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: MEDIUMDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes the
!command syntax to execute a shell command automatically when the skill is loaded. The commandbash "${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh" resolve_config --keys automationuses path traversal to execute a script located outside of the skill's specific directory. - [INDIRECT_PROMPT_INJECTION]: The skill processes various external and potentially untrusted data sources to generate player-facing patch notes.
- Ingestion points: The skill ingests text from
git log,production/releases/,docs/CHANGELOG.md,production/sprints/,design/balance/, and QA bug records. - Boundary markers: There are no explicit delimiters or boundary markers used to separate untrusted ingested data from the skill's instructions.
- Capability inventory: The skill has the capability to write to the file system (
Write) and execute shell commands (Bash). - Sanitization: The skill does not implement sanitization, filtering, or escaping for the data read from logs or external files before it is processed by the model.
- [COMMAND_EXECUTION]: The skill relies on shell commands for repository analysis (
git log) and project configuration resolution via a custom bash hook.
Audit Metadata