product-changelog

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references installation instructions for the belt CLI hosted on GitHub (inference-sh/skills). These references are for documentation purposes to help the user set up the required environment.
  • [COMMAND_EXECUTION]: The skill provides examples of executing commands via the belt CLI to run specific AI applications (e.g., falai/flux-dev-lora, bytedance/seededit-3-0-i2i). These commands are intended to assist the user in generating visual assets for their changelogs.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied text for release notes.
  • Ingestion points: Product update descriptions and feature details provided by the user in SKILL.md.
  • Boundary markers: The skill provides formatting templates but does not specify explicit delimiters for user content.
  • Capability inventory: The skill utilizes belt app run to invoke remote tools based on the generated content.
  • Sanitization: No explicit sanitization or filtering is described for the input data.
  • [SAFE]: The skill operates within its stated purpose of document generation and visual asset creation. All external tools and sources referenced are legitimate services within the AI development ecosystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 08:14 PM
Security Audit — agent-trust-hub — product-changelog