release-and-changelog
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill involves downloading and installing packages from registries during the release verification stage in Step 6.
- [COMMAND_EXECUTION]: The skill executes local git commands and package manager tools to manage versioning and publishing as described in Steps 1, 4, 5, and 6.
- [INDIRECT_PROMPT_INJECTION]: The skill parses untrusted data from the project's commit history and changelog. Ingestion points: git log in Step 1 and CHANGELOG.md in Step 2. Boundary markers: None. Capability inventory: File system writing, repository manipulation, and package publishing. Sanitization: None.
Audit Metadata