create-rc-tag
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes standard Git commands to manage repository tags and branches.
- Evidence includes:
git ls-remote,git fetch,git tag -s, andgit pushoperations. - Safety measures: The skill implements strict regex validation for user-provided inputs (
BASE_VERSIONandRC_NUMBER) to prevent command injection. It targets the officialNVIDIA/NeMo-Relayrepository, uses signed tags (-s) for authenticity, and explicitly requires user approval before pushing changes. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied version strings, which represents a potential injection surface.
- Ingestion points:
BASE_VERSIONandRC_NUMBERvariables inSKILL.md. - Boundary markers: Strict Bash regex markers (
^...$) are used to delimit inputs. - Capability inventory: The skill has the capability to write to a remote repository via
git push. - Sanitization: Inputs are rigorously validated against numeric patterns (
^[0-9]+\.[0-9]+...$), effectively neutralizing the risk of malicious instruction injection through these fields.
Audit Metadata