release-openspec

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: Uses git commands (fetch, log, worktree) and gh commands (pr list, release edit, api) to manage the release lifecycle of the repository.
  • [COMMAND_EXECUTION]: Employs pnpm exec changeset to calculate versions and update changelogs based on local changeset files.
  • [EXTERNAL_DOWNLOADS]: Interacts with GitHub APIs and the NPM registry to synchronize repository state and verify artifact publishing.
  • [PROMPT_INJECTION]: Processes external data from Pull Request titles and descriptions to generate release notes. The skill mitigates risks by instructing the agent to cross-check content against the formal CHANGELOG.md and strictly follow a structured release note template.
  • [SAFE]: Implements security boundaries, including repository owner validation and a prohibition on self-approving pull requests.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 07:22 PM
Security Audit — agent-trust-hub — release-openspec