warp-changelog-audit
Fail
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: HIGHCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands for repository management and verification. Specifically, Phase 4 directs the agent to write a temporary script and run it with
uv runto verify runtime claims in changelog fragments. It also states that if native code changed, the agent should rebuild the project, which could trigger code execution via the build system. - [DYNAMIC_EXECUTION]: The skill uses dynamic code generation and execution. In Phase 4, the agent is directed to create temporary Python scripts based on content found in external, untrusted changelog fragments. This pattern is susceptible to injection where external data influences the logic of the executed script.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from changelog fragments and Git history. The instructions state that the external
changelog/README.mdis authoritative, creating a surface for overriding agent behavior. 1. Ingestion points:changelog/*.md,changelog/README.md, andgit log. 2. Boundary markers: None provided in the instructions. 3. Capability inventory: Execution of scripts (uv run), tool installation (uvx), and repository modification (git commit). 4. Sanitization: No validation or filtering of fragment content is specified. - [REMOTE_CODE_EXECUTION]: The agent is directed to execute code generated from untrusted external inputs via
uv run. A malicious changelog fragment could lead to arbitrary code execution during this verification process. - [EXTERNAL_DOWNLOADS]: The skill fetches the
towncrierpackage (version 25.8.0) from the official Python Package Index (PyPI) usinguvx. Theuv runcommand may also trigger downloads of project dependencies.
Recommendations
- AI detected serious security threats
Audit Metadata