ppt-release

Pass

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill performs shell-based operations including git commands (commit, tag, push) and several local quality-check tools (sip, re0-git, shower, factchk, mandela, ssotchk, ssotize, re0). These commands are essential to the skill's primary purpose of automating a release workflow and are executed based on the user's explicit invocation.\n- [PROMPT_INJECTION]: The skill ingests untrusted data from the repository (e.g., git diffs, READMEs, and other SKILL.md files) to verify shipping readiness. This content could theoretically contain instructions to subvert the release process.\n
  • Ingestion points: Git diffs and repository files (SKILL.md, README, plugin.json) are read in Step 1 and Step 3.\n
  • Boundary markers: No explicit delimiters are used to separate untrusted data from instructions.\n
  • Capability inventory: The skill executes shell commands for git operations and quality tools (sip, re0-git, etc.) in Steps 3, 6, and 8.\n
  • Sanitization: No explicit sanitization of the ingested repository content is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 8, 2026, 09:18 AM
Security Audit — agent-trust-hub — ppt-release