update-project-version
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill facilitates standard software release procedures for the NeMo Fabric project. The instructions are specific, include safety warnings, and incorporate rigorous validation steps using project-native tools.
- [COMMAND_EXECUTION]: The skill automates version updates using a just command runner recipe and performs verification via cargo, npm, and ripgrep as described in SKILL.md. These actions are well-scoped and appropriate for the skill's intended development context.
- [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by processing version metadata from project files and user input to perform file updates. 1. Ingestion points: Version strings are read from Cargo.toml (SKILL.md) and user input. 2. Boundary markers: None explicitly defined in the skill instructions. 3. Capability inventory: The skill uses just, cargo, rg, and git to modify files and validate builds (SKILL.md). 4. Sanitization: The skill relies on the just set-version recipe and manual audit steps to ensure the integrity of the updates.
Audit Metadata