prepare-release
Pass
Audited by Gen Agent Trust Hub on Jul 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements significant safety measures for handling repository metadata and history. It treats version strings and Git references as untrusted data, requiring validation and resolution to exact object IDs (OIDs) to prevent command or path injection.
- [COMMAND_EXECUTION]: While the skill may run local generation tools or release scripts, it requires that these tools be "reviewed" and mandates user confirmation for any scripts with potential network, credential, or destructive side effects. It explicitly prohibits publishing, uploading, or deploying artifacts, keeping actions local to the repository.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data (commit messages, repository files). It mitigates the risk of indirect prompt injection by using explicit "execute-update" mode requirements, validating ref syntax, and avoiding automatic semantic versioning decisions based solely on commit prefixes.
Audit Metadata