gen-release-notes
Warn
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the user-provided
$ARGUMENTSvariable in several shell commands without consistent quoting. While some uses are quoted, the variable expansion${PREV_TAG}is unquoted in commands such asgit log ${PREV_TAG}..HEADandgit diff ${PREV_TAG}..HEAD. This could allow a malicious user to inject shell metacharacters (e.g.,;,&,|) to execute unauthorized commands. Although a check for the existence of the tag in Step 1 acts as a partial mitigation, the unquoted expansion remains a vulnerability if the gate is bypassed or improperly handled by the agent. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external repository sources which could contain malicious instructions designed to influence the agent or the verification script.
- Ingestion points: Step 1 collects information from
git logandgh pr list, which include commit messages, PR titles, and author names created by external contributors. - Boundary markers: The skill does not use explicit delimiters or instructions to ignore embedded commands within the ingested data during the generation phase.
- Capability inventory: The skill utilizes
gitandghCLI tools and executes complex shell script logic (Step 6) that processes the aggregated content. - Sanitization: There is no evidence of sanitization or escaping of the commit messages or PR titles before they are written to
CHANGELOG.md. This content is subsequently processed by shell commands likegrepandsedin the "HARD GATE" verification step, where specifically crafted text in a commit message could potentially disrupt script execution or manipulate version extraction logic.
Audit Metadata