release-doc
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill performs repository analysis using standard local shell commands including
git log,git diff,git show,mkdir, andgrep. These are used to extract history and manage artifact files locally. - [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection (Category 8) by ingesting untrusted data from the repository's git history.
- Ingestion points: Git log metadata, commit bodies, and code diffs are read from
docs/release/and processed for narrative generation in Steps 4 and 6. - Boundary markers: There are no explicit delimiters or 'ignore embedded instructions' warnings provided to the agent when it analyzes these git artifacts.
- Capability inventory: The agent possesses capabilities for shell command execution (
git) and filesystem modification (mkdir, writing docs). - Sanitization: The protocol lacks a sanitization step to filter out potentially malicious instructions hidden in commit messages before they are processed by the LLM.
Audit Metadata