release-planner

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes untrusted external data.\n
  • Ingestion points: Processes data from steering documents (documentation/steering/product.md) and external stakeholder requests as described in Step 3.\n
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are specified for the processed content.\n
  • Capability inventory: The skill can write files to the local repository (documentation/releases/) and perform API operations (create epics/pages) on external platforms via adapters.\n
  • Sanitization: There is no evidence of validation or sanitization of the input data before it is used to generate tracker items or documentation.\n- [DATA_EXFILTRATION]: The skill transmits project metadata and feature descriptions to external platforms including Jira, Confluence, Notion, and Azure DevOps. This is consistent with the skill's intended purpose and targets well-known, established services.\n- [COMMAND_EXECUTION]: Automated actions are performed on integrated task trackers and documentation suites via external adapter scripts. These executions are scoped to the project environments configured by the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 01:24 PM
Security Audit — agent-trust-hub — release-planner