changelog-release-notes-weapon

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill includes integration instructions for several established changelog service providers. These instructions involve standard CDN script tags (from headwayapp.co, productlane.com, and getbeamer.com) and the official FeatureBase React library (@featurebase/react). These are legitimate resources used for their intended primary purpose.
  • [PROMPT_INJECTION]: The skill identifies a data ingestion surface where it processes developer-provided logs and pull request descriptions. However, it mitigates potential indirect prompt injection by instructing the agent to actively rewrite and frame this data for end-users, rather than treating it as executable instructions. Furthermore, the skill does not have access to sensitive tools or file system operations that could be exploited.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 03:22 AM
Security Audit — agent-trust-hub — changelog-release-notes-weapon