version-management
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill consists entirely of Markdown documentation, guidelines, and templates. It does not include any scripts, executables, or binary files.
- [SAFE]: External references in the documentation point exclusively to trusted official specifications (e.g., semver.org, python.org, kubernetes.io), academic sources (IEEE, ScienceDirect), and well-known industry blogs.
- [SAFE]: No patterns of prompt injection, obfuscation, privilege escalation, or data exfiltration were found in the instructional text or metadata.
- [INDIRECT_PROMPT_INJECTION]: The skill guides the agent to process external data sources such as project manifest files (
package.json,Cargo.toml) and changelogs. While these ingestion points represent a potential surface for indirect prompt injection if the files were maliciously crafted by an attacker, the skill itself provides structured methodologies and emphasizes human review of changes.
Audit Metadata