release-and-changelog

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill involves downloading and installing packages from registries during the release verification stage in Step 6.
  • [COMMAND_EXECUTION]: The skill executes local git commands and package manager tools to manage versioning and publishing as described in Steps 1, 4, 5, and 6.
  • [INDIRECT_PROMPT_INJECTION]: The skill parses untrusted data from the project's commit history and changelog. Ingestion points: git log in Step 1 and CHANGELOG.md in Step 2. Boundary markers: None. Capability inventory: File system writing, repository manipulation, and package publishing. Sanitization: None.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:33 PM
Security Audit — agent-trust-hub — release-and-changelog