create-release-tag

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFENO_CODECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for Git operations while enforcing strict safety protocols, such as mandatory use of 'git check-ref-format' for tag validation and explicit prohibition of broad push operations like '--tags'.
  • [PROMPT_INJECTION]: The skill identifies a potential surface for indirect prompt injection via user-supplied tag names and messages. It mitigates this by instructing the agent to treat all inputs as untrusted and resolving all identifiers to exact OIDs. Evidence chain: (1) Ingestion points: User-defined tag names and messages (SKILL.md). (2) Boundary markers: Explicit instructions to treat all inputs as untrusted. (3) Capability inventory: Local 'git tag' creation and 'git push' operations. (4) Sanitization: Mandatory use of 'git check-ref-format' and OID resolution.
  • [NO_CODE]: The skill contains no executable scripts or binaries, consisting entirely of instructional guidelines.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 04:50 PM
Security Audit — agent-trust-hub — create-release-tag