changelog-release-notes-weapon
Pass
Audited by Gen Agent Trust Hub on Jul 25, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill includes integration instructions for several established changelog service providers. These instructions involve standard CDN script tags (from headwayapp.co, productlane.com, and getbeamer.com) and the official FeatureBase React library (@featurebase/react). These are legitimate resources used for their intended primary purpose.
- [PROMPT_INJECTION]: The skill identifies a data ingestion surface where it processes developer-provided logs and pull request descriptions. However, it mitigates potential indirect prompt injection by instructing the agent to actively rewrite and frame this data for end-users, rather than treating it as executable instructions. Furthermore, the skill does not have access to sensitive tools or file system operations that could be exploited.
Audit Metadata