gen-release-notes

Warn

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the user-provided $ARGUMENTS variable in several shell commands without consistent quoting. While some uses are quoted, the variable expansion ${PREV_TAG} is unquoted in commands such as git log ${PREV_TAG}..HEAD and git diff ${PREV_TAG}..HEAD. This could allow a malicious user to inject shell metacharacters (e.g., ;, &, |) to execute unauthorized commands. Although a check for the existence of the tag in Step 1 acts as a partial mitigation, the unquoted expansion remains a vulnerability if the gate is bypassed or improperly handled by the agent.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external repository sources which could contain malicious instructions designed to influence the agent or the verification script.
  • Ingestion points: Step 1 collects information from git log and gh pr list, which include commit messages, PR titles, and author names created by external contributors.
  • Boundary markers: The skill does not use explicit delimiters or instructions to ignore embedded commands within the ingested data during the generation phase.
  • Capability inventory: The skill utilizes git and gh CLI tools and executes complex shell script logic (Step 6) that processes the aggregated content.
  • Sanitization: There is no evidence of sanitization or escaping of the commit messages or PR titles before they are written to CHANGELOG.md. This content is subsequently processed by shell commands like grep and sed in the "HARD GATE" verification step, where specifically crafted text in a commit message could potentially disrupt script execution or manipulate version extraction logic.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 20, 2026, 09:16 AM
Security Audit — agent-trust-hub — gen-release-notes