update-project-version

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill facilitates standard software release procedures for the NeMo Fabric project. The instructions are specific, include safety warnings, and incorporate rigorous validation steps using project-native tools.
  • [COMMAND_EXECUTION]: The skill automates version updates using a just command runner recipe and performs verification via cargo, npm, and ripgrep as described in SKILL.md. These actions are well-scoped and appropriate for the skill's intended development context.
  • [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by processing version metadata from project files and user input to perform file updates. 1. Ingestion points: Version strings are read from Cargo.toml (SKILL.md) and user input. 2. Boundary markers: None explicitly defined in the skill instructions. 3. Capability inventory: The skill uses just, cargo, rg, and git to modify files and validate builds (SKILL.md). 4. Sanitization: The skill relies on the just set-version recipe and manual audit steps to ensure the integrity of the updates.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 12:08 AM
Security Audit — agent-trust-hub — update-project-version