product-changelog

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS] Fetches CLI installation guidelines and documentation from the inference-sh official GitHub repository.
  • [COMMAND_EXECUTION] The skill is authorized to use the belt CLI tool via Bash(belt *), allowing for authentication (belt login) and execution of various vendor-provided modules like agent-browser and flux-dev-lora to generate screenshots and visuals.
  • [INDIRECT_PROMPT_INJECTION] The skill's primary function involves processing external developer data (commit messages, PR descriptions, and issue logs) as untrusted input. This creates a surface where embedded instructions could attempt to influence the agent's changelog output or broader behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 05:09 PM
Security Audit — agent-trust-hub — product-changelog