lov-release-via-cicd

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the target repository to automate release workflows.
  • Ingestion points: The skill reads package.json, CHANGELOG.md, and Git history to determine version increments and generate release notes (SKILL.md Workflow steps 1 and 4).
  • Boundary markers: No explicit instruction delimiters or 'ignore embedded instructions' warnings are provided when processing these files.
  • Capability inventory: The skill possesses the capability to execute shell commands via git and gh (GitHub CLI), write to local profile files via scripts/profile_store.py, and perform file-system operations during the build process.
  • Sanitization: The skill uses yaml.safe_load for parsing configuration files and filters sensitive metadata keys (tokens, secrets) within its profile management script.
  • [COMMAND_EXECUTION]: The skill relies on external CLI tools to perform its primary functions.
  • Evidence: Instructions in SKILL.md and references/tauri-release-workflow.md explicitly direct the agent to use git, gh, npx, and platform-specific build tools like codesign and spctl for binary verification.
  • [EXTERNAL_DOWNLOADS]: The skill provides templates that reference well-known and trusted external resources for CI/CD setup.
  • Evidence: The workflow playbooks in references/general-release-playbooks.md and references/tauri-release-workflow.md use standard, widely recognized GitHub Actions such as actions/checkout, pnpm/action-setup, actions/setup-node, and tauri-apps/tauri-action.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 10:08 PM
Security Audit — agent-trust-hub — lov-release-via-cicd