flag-release

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Utilizes authorized MCP tools such as get-flag, match-release-policies, and create-automated-rollout-config specifically designed for LaunchDarkly feature management.
  • [EXTERNAL_DOWNLOADS]: References the @launchdarkly/mcp-server package, which is an official resource provided by the skill author and hosted on a trusted registry.
  • [DATA_EXFILTRATION]: Contains explicit instructions to prevent the agent from printing or handling credentials, relying on environmental security for access rather than manual secret handling.
  • [PROMPT_INJECTION]: The skill processes external data including pull request references and human release intent which are used as parameters for rollout configurations. It implements a plan-and-confirm phase to ensure human oversight before executing the automated rollout.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 12:56 AM
Security Audit — agent-trust-hub — flag-release