release
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an ingestion surface for potentially untrusted data that could be leveraged for indirect prompt injection attacks.
- Ingestion points: Processes external inputs from git history logs via
git log --oneline --no-mergesand custom changelog files atreleases/vYYYY.MDD.P.md. - Boundary markers: No specific delimiters or boundary instructions are present to prevent the agent from obeying instructions embedded inside commit messages or changelog markdown files.
- Capability inventory: Possesses capabilities to execute multiple local shell scripts (
./scripts/release.sh,./scripts/docker-onboard-smoke.sh,./scripts/create-github-release.sh) and perform HTTP operations (POST /api/companies/:companyId/cases). - Sanitization: Lacks active sanitization or verification filters on input parsed from the git commit logs or changelog files.
- [COMMAND_EXECUTION]: Executes several repository-contained maintenance scripts (
./scripts/release.sh,./scripts/docker-onboard-smoke.sh, etc.) and standard ecosystem tools (pnpm,npm,git). These operations are safe within the local workspace context and represent standard software release activities for the paperclipai product.
Audit Metadata