flag-release
Pass
Audited by Gen Agent Trust Hub on Jul 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Utilizes authorized MCP tools such as get-flag, match-release-policies, and create-automated-rollout-config specifically designed for LaunchDarkly feature management.
- [EXTERNAL_DOWNLOADS]: References the @launchdarkly/mcp-server package, which is an official resource provided by the skill author and hosted on a trusted registry.
- [DATA_EXFILTRATION]: Contains explicit instructions to prevent the agent from printing or handling credentials, relying on environmental security for access rather than manual secret handling.
- [PROMPT_INJECTION]: The skill processes external data including pull request references and human release intent which are used as parameters for rollout configurations. It implements a plan-and-confirm phase to ensure human oversight before executing the automated rollout.
Audit Metadata