create-release-tag

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill automates high-privilege repository operations such as git push and gh release create. It incorporates safety measures including local state verification, version string validation, and mandatory user approval prior to remote operations.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes project documentation to generate release summaries, creating a potential vector for indirect prompt injection.
  • Ingestion points: Reads release notes from docs/about-nemo-relay/release-notes/index.mdx.
  • Boundary markers: No delimiters are used to isolate the ingested text from the agent's instructions.
  • Capability inventory: The skill utilizes git and gh tools for repository management.
  • Sanitization: No content filtering or sanitization is applied to the documentation file before it is summarized.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 05:19 PM
Security Audit — agent-trust-hub — create-release-tag