skills/paperclipai/paperclip/release/Gen Agent Trust Hub

release

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an ingestion surface for potentially untrusted data that could be leveraged for indirect prompt injection attacks.
  • Ingestion points: Processes external inputs from git history logs via git log --oneline --no-merges and custom changelog files at releases/vYYYY.MDD.P.md.
  • Boundary markers: No specific delimiters or boundary instructions are present to prevent the agent from obeying instructions embedded inside commit messages or changelog markdown files.
  • Capability inventory: Possesses capabilities to execute multiple local shell scripts (./scripts/release.sh, ./scripts/docker-onboard-smoke.sh, ./scripts/create-github-release.sh) and perform HTTP operations (POST /api/companies/:companyId/cases).
  • Sanitization: Lacks active sanitization or verification filters on input parsed from the git commit logs or changelog files.
  • [COMMAND_EXECUTION]: Executes several repository-contained maintenance scripts (./scripts/release.sh, ./scripts/docker-onboard-smoke.sh, etc.) and standard ecosystem tools (pnpm, npm, git). These operations are safe within the local workspace context and represent standard software release activities for the paperclipai product.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:47 PM
Security Audit — agent-trust-hub — release