semantic-version

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted project data such as code diffs to generate version summaries. While this constitutes an attack surface, the risk is mitigated by the skill's limited capabilities, which are restricted to updating structured local files (docs/release-history.json, package.json) without executing commands or making network requests based on the ingested content.
  • [SAFE]: The skill provides clear, restricted instructions for managing project metadata and does not attempt to access sensitive files, environment variables, or external resources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 10:08 PM
Security Audit — agent-trust-hub — semantic-version