release-doc

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill performs repository analysis using standard local shell commands including git log, git diff, git show, mkdir, and grep. These are used to extract history and manage artifact files locally.
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection (Category 8) by ingesting untrusted data from the repository's git history.
  • Ingestion points: Git log metadata, commit bodies, and code diffs are read from docs/release/ and processed for narrative generation in Steps 4 and 6.
  • Boundary markers: There are no explicit delimiters or 'ignore embedded instructions' warnings provided to the agent when it analyzes these git artifacts.
  • Capability inventory: The agent possesses capabilities for shell command execution (git) and filesystem modification (mkdir, writing docs).
  • Sanitization: The protocol lacks a sanitization step to filter out potentially malicious instructions hidden in commit messages before they are processed by the LLM.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 08:22 PM
Security Audit — agent-trust-hub — release-doc