check-release-deployments

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes several CLI tools including gh (GitHub CLI), just (command runner), uv (Python toolchain), and python to perform status checks and environment discovery. All inputs, such as the release tag, are strictly validated against a semantic versioning regex (^[0-9]+\.[0-9]+\.[0-9]+(-((alpha|beta|rc)\.[0-9]+))?$) before being used in commands.
  • [EXTERNAL_DOWNLOADS]: The script performs HTTP GET requests via curl to fetch status information from well-known package registries (PyPI, crates.io, and npmjs.org) and retrieves the go.mod file from the official NVIDIA/NeMo-Relay GitHub repository. These operations are diagnostic in nature and target trusted or well-known services.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources, such as GitHub Actions job concludes and registry version lists. This data is strictly parsed using jq and formatted into a markdown report for the agent. The use of strict parsing and specific field extraction minimizes the risk of the agent misinterpreting external content as instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 05:19 PM
Security Audit — agent-trust-hub — check-release-deployments