flag-release
Pass
Audited by Gen Agent Trust Hub on Aug 3, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill uses official LaunchDarkly MCP tools to manage feature flags. No malicious code, obfuscation, or unauthorized access patterns were detected. All network interactions are limited to the vendor's managed infrastructure.- [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill processes data from LaunchDarkly and GitHub. 1. Ingestion points: get-flag, match-release-policies tools, and PR metadata. 2. Boundary markers: Absent. 3. Capability inventory: Automated rollout configuration updates (network write). 4. Sanitization: Absent. The risk is mitigated by explicit instructions to honor human release intent.
Audit Metadata