release-planner
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes untrusted external data.\n
- Ingestion points: Processes data from steering documents (
documentation/steering/product.md) and external stakeholder requests as described in Step 3.\n - Boundary markers: No explicit delimiters or instructions to ignore embedded commands are specified for the processed content.\n
- Capability inventory: The skill can write files to the local repository (
documentation/releases/) and perform API operations (create epics/pages) on external platforms via adapters.\n - Sanitization: There is no evidence of validation or sanitization of the input data before it is used to generate tracker items or documentation.\n- [DATA_EXFILTRATION]: The skill transmits project metadata and feature descriptions to external platforms including Jira, Confluence, Notion, and Azure DevOps. This is consistent with the skill's intended purpose and targets well-known, established services.\n- [COMMAND_EXECUTION]: Automated actions are performed on integrated task trackers and documentation suites via external adapter scripts. These executions are scoped to the project environments configured by the user.
Audit Metadata