product-changelog
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS] Fetches CLI installation guidelines and documentation from the inference-sh official GitHub repository.
- [COMMAND_EXECUTION] The skill is authorized to use the
beltCLI tool viaBash(belt *), allowing for authentication (belt login) and execution of various vendor-provided modules likeagent-browserandflux-dev-lorato generate screenshots and visuals. - [INDIRECT_PROMPT_INJECTION] The skill's primary function involves processing external developer data (commit messages, PR descriptions, and issue logs) as untrusted input. This creates a surface where embedded instructions could attempt to influence the agent's changelog output or broader behavior.
Audit Metadata