release-please-protection

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill functions as a set of behavioral instructions for the agent. It proactively identifies sensitive project files (like CHANGELOG.md and package manifests) and provides response templates to explain why manual edits are restricted in environments using 'release-please' automation.
  • [SAFE]: The detection logic relies on standard regex patterns to identify version fields in configuration files (package.json, pyproject.toml, etc.). These patterns are used for passive detection and do not involve the execution of untrusted data or complex logic that could be exploited.
  • [SAFE]: Documentation provided in the 'Emergency Overrides' and 'Workflow Guide' sections describes standard developer workflows using the 'git' and 'gh' (GitHub) CLI tools. These instructions are intended for the user and do not grant the agent unauthorized capabilities or perform hidden network operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 08:39 PM
Security Audit — agent-trust-hub — release-please-protection