release-checklist

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses a restricted Bash tool to execute a local project script named yaml-helper.sh. The tool definition in the skill's frontmatter limits the command to this specific script path to prevent arbitrary command execution.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill employs the ! command syntax to run a shell command at the time the skill is loaded. Specifically, it executes bash "${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh" resolve_config to retrieve project settings such as rigor levels and certification targets. This is used for legitimate project-specific configuration resolution.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data by scanning source code files for comments (TODO, FIXME, HACK) and including their content in the final checklist.
  • Ingestion points: Source files are read using the Glob and Grep tools.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to ignore potentially malicious instructions embedded within the scanned code comments.
  • Capability inventory: The skill has the ability to write files to the production/releases/ directory and execute a specific local bash script.
  • Sanitization: The skill does not perform sanitization or escaping of the scanned comment text before it is presented in the markdown report.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:51 PM
Security Audit — agent-trust-hub — release-checklist