warp-changelog-audit

Fail

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: HIGHCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands for repository management and verification. Specifically, Phase 4 directs the agent to write a temporary script and run it with uv run to verify runtime claims in changelog fragments. It also states that if native code changed, the agent should rebuild the project, which could trigger code execution via the build system.
  • [DYNAMIC_EXECUTION]: The skill uses dynamic code generation and execution. In Phase 4, the agent is directed to create temporary Python scripts based on content found in external, untrusted changelog fragments. This pattern is susceptible to injection where external data influences the logic of the executed script.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from changelog fragments and Git history. The instructions state that the external changelog/README.md is authoritative, creating a surface for overriding agent behavior. 1. Ingestion points: changelog/*.md, changelog/README.md, and git log. 2. Boundary markers: None provided in the instructions. 3. Capability inventory: Execution of scripts (uv run), tool installation (uvx), and repository modification (git commit). 4. Sanitization: No validation or filtering of fragment content is specified.
  • [REMOTE_CODE_EXECUTION]: The agent is directed to execute code generated from untrusted external inputs via uv run. A malicious changelog fragment could lead to arbitrary code execution during this verification process.
  • [EXTERNAL_DOWNLOADS]: The skill fetches the towncrier package (version 25.8.0) from the official Python Package Index (PyPI) using uvx. The uv run command may also trigger downloads of project dependencies.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 24, 2026, 04:53 AM
Security Audit — agent-trust-hub — warp-changelog-audit