release-skills
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill performs extensive shell command execution using standard development tools like
gitandgh(GitHub CLI). It uses these tools to analyze repository history, stage changes, commit new versions, tag releases, and push to remote repositories. - [DYNAMIC_EXECUTION]: The skill supports a configuration file (
.releaserc.yml) that can define arbitrary shell commands as hooks forprepare_artifactandpublish_artifact. These hooks allow the skill to execute project-specific logic defined within the repository, which constitutes dynamic execution of commands based on local configuration. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the project's git history to automate versioning and documentation.
- Ingestion points: Commit messages retrieved via
git logand PR author information retrieved viagh pr vieware used to populate changelogs and determine SemVer bumps. - Boundary markers: While the skill instructions specify separating changelog content into a temporary file, there are no explicit boundary markers or instructions to the model to ignore potential directives embedded within commit messages.
- Capability inventory: The skill has the capability to write to the local filesystem, commit changes to the repository, push to remote servers, and execute arbitrary shell hooks.
- Sanitization: The skill mitigates basic command injection by writing multi-line content (like release notes) to temporary UTF-8 files rather than inlining the text directly into shell arguments.
Audit Metadata