project-release-maintainer

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill contains no evidence of malicious patterns, obfuscation, or unauthorized data access. It defines a workflow for managing project releases using existing repository tools and verification steps.
  • [INDIRECT_PROMPT_INJECTION]: The skill presents an inherent surface for indirect prompt injection by instructing the agent to ingest external repository data such as package manifests, install rules, and shipped assets. * Ingestion points: Package manifests, install rules, assets, and documentation (SKILL.md). * Boundary markers: Explicit instructions to treat tagging, publishing, and credential use as separate actions requiring authorization serve as functional boundaries. * Capability inventory: Edit capabilities and execution of repository-specific verification commands (SKILL.md). * Sanitization: Not explicitly defined for the ingested data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 05:58 PM
Security Audit — agent-trust-hub — project-release-maintainer