check-release-deployments
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes several CLI tools including
gh(GitHub CLI),just(command runner),uv(Python toolchain), andpythonto perform status checks and environment discovery. All inputs, such as the release tag, are strictly validated against a semantic versioning regex (^[0-9]+\.[0-9]+\.[0-9]+(-((alpha|beta|rc)\.[0-9]+))?$) before being used in commands. - [EXTERNAL_DOWNLOADS]: The script performs HTTP GET requests via
curlto fetch status information from well-known package registries (PyPI, crates.io, and npmjs.org) and retrieves thego.modfile from the official NVIDIA/NeMo-Relay GitHub repository. These operations are diagnostic in nature and target trusted or well-known services. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources, such as GitHub Actions job concludes and registry version lists. This data is strictly parsed using
jqand formatted into a markdown report for the agent. The use of strict parsing and specific field extraction minimizes the risk of the agent misinterpreting external content as instructions.
Audit Metadata