create-release-tag
Pass
Audited by Gen Agent Trust Hub on Jul 1, 2026
Risk Level: SAFENO_CODECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for Git operations while enforcing strict safety protocols, such as mandatory use of 'git check-ref-format' for tag validation and explicit prohibition of broad push operations like '--tags'.
- [PROMPT_INJECTION]: The skill identifies a potential surface for indirect prompt injection via user-supplied tag names and messages. It mitigates this by instructing the agent to treat all inputs as untrusted and resolving all identifiers to exact OIDs. Evidence chain: (1) Ingestion points: User-defined tag names and messages (SKILL.md). (2) Boundary markers: Explicit instructions to treat all inputs as untrusted. (3) Capability inventory: Local 'git tag' creation and 'git push' operations. (4) Sanitization: Mandatory use of 'git check-ref-format' and OID resolution.
- [NO_CODE]: The skill contains no executable scripts or binaries, consisting entirely of instructional guidelines.
Audit Metadata