om-auto-update-changelog

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted data from pull request bodies and repository configurations. It mitigates this surface by implementing an 'Untrusted content boundary' in references/agentic-setup.md, which explicitly directs the agent to ignore embedded instructions and validate all external values before use.
  • [COMMAND_EXECUTION]: Shell and git commands are used for repository analysis. These are strictly confined to the project directory and follow established tracker descriptors, ensuring no unauthorized system access.
  • [DATA_EXPOSURE]: The skill implements a 'Secrets hygiene' rule in references/rules.md that redacts credentials and prevents sensitive environment data from being included in changelogs or reports.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 12:19 AM
Security Audit — agent-trust-hub — om-auto-update-changelog