release-skills

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill performs extensive shell command execution using standard development tools like git and gh (GitHub CLI). It uses these tools to analyze repository history, stage changes, commit new versions, tag releases, and push to remote repositories.
  • [DYNAMIC_EXECUTION]: The skill supports a configuration file (.releaserc.yml) that can define arbitrary shell commands as hooks for prepare_artifact and publish_artifact. These hooks allow the skill to execute project-specific logic defined within the repository, which constitutes dynamic execution of commands based on local configuration.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the project's git history to automate versioning and documentation.
  • Ingestion points: Commit messages retrieved via git log and PR author information retrieved via gh pr view are used to populate changelogs and determine SemVer bumps.
  • Boundary markers: While the skill instructions specify separating changelog content into a temporary file, there are no explicit boundary markers or instructions to the model to ignore potential directives embedded within commit messages.
  • Capability inventory: The skill has the capability to write to the local filesystem, commit changes to the repository, push to remote servers, and execute arbitrary shell hooks.
  • Sanitization: The skill mitigates basic command injection by writing multi-line content (like release notes) to temporary UTF-8 files rather than inlining the text directly into shell arguments.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 02:56 AM
Security Audit — agent-trust-hub — release-skills