maven-release-validation
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted project data (POM files, Git logs), creating a surface where malicious content could influence the agent's behavior.
- Ingestion points: Reads repository hierarchy, POM files, and Git metadata from the local workspace.
- Boundary markers: Lacks explicit instructions to ignore natural language commands that might be embedded in data files.
- Capability inventory: Executes mvn and git commands, which can perform file system and network operations.
- Sanitization: Explicitly requires the redaction of tokens, passwords, and private credentials in all output and logs.
Audit Metadata