release-archivist

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill evaluates untrusted data from external sources to determine the workflow verdict. \n
  • Ingestion points: Captures data from the output and exit codes of test suites, linters, and build commands in SKILL.md.\n
  • Boundary markers: Lacks explicit instructions for delimiting or ignoring embedded instructions within the captured command outputs.\n
  • Capability inventory: Includes the ability to set workflow state, transition states, and perform physical archive actions such as merging branches and removing worktrees via the ssf utility.\n
  • Sanitization: No evidence of sanitization or strict schema validation for the external output before it is used to influence the agent's decision-making process.\n- [COMMAND_EXECUTION]: The skill performs shell command execution to facilitate the release process. \n
  • Utilizes the ssf command-line utility for state management and auditing.\n
  • Executes project-specific test suites, including an optional override command via the --test-cmd flag in the ssf finish routine.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 04:27 PM
Security Audit — agent-trust-hub — release-archivist