skills/nvidia/warp/warp-release-audit/Gen Agent Trust Hub

warp-release-audit

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes shell commands to interact with the project's Git repository and the GitHub CLI (gh). This includes operations to list commits, manage temporary worktrees, and publish audit reports to GitHub Gists. These actions are aligned with the skill's intended purpose of release auditing.
  • [DYNAMIC_EXECUTION]: To verify if changes are source-breaking, the skill directs the agent to generate and execute minimal Python test scripts (Phase 4g). These scripts are used to compare the behavior of the library at different Git references and capture output differences.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the repository, creating a vulnerability surface for indirect prompt injection.
  • Ingestion points: The agent processes CHANGELOG.md, Towncrier fragments from the changelog/ directory, and Git commit metadata (subjects and diffs).
  • Boundary markers: No specific delimiters or safety instructions are defined in the skill to isolate untrusted repository data from the agent's reasoning process.
  • Capability inventory: Across its scripts and instructions, the skill has capabilities including shell command execution, network access via gh, and execution of generated Python code.
  • Sanitization: The skill lacks explicit sanitization or validation of the text content extracted from the repository before it is used for analysis or code generation.
  • [EXTERNAL_DOWNLOADS]: The skill downloads and runs the towncrier package (version 25.8.0) from a standard package registry using uvx to generate temporary changelog drafts during the audit process.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 04:53 AM
Security Audit — agent-trust-hub — warp-release-audit