ln-62-release-publisher
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from git commit histories and source diffs to generate release notes and summaries.
- Ingestion points: The agent reads repository commit messages, full commit bodies, and manifest files (
SKILL.md) to determine release scope. - Boundary markers: The instructions do not define specific prompt delimiters to isolate ingested commit data from the system prompt, though it mandates a strict 'Execution contract' for evidence verification.
- Capability inventory: The skill has the authority to commit and push changes, create git tags, and publish GitHub Releases through the hosting API.
- Sanitization: The skill employs safety measures by using temporary files for shell commands to prevent command injection from notes content and requires explicit user approval of the final generated proposal before any publication action occurs.
Audit Metadata