release

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The release workflow relies on a multi-step chain where the review-agent evaluates the output of previous scan and test phases.
  • Ingestion points: The sub-agent prompt for review-agent in SKILL.md explicitly ingests security audit results, test results, and git logs.
  • Boundary markers: There are no delimiters or 'ignore embedded instructions' warnings provided in the prompt templates to distinguish between agent instructions and data from external reports.
  • Capability inventory: The workflow includes capabilities to modify project files (package.json, pyproject.toml, CHANGELOG.md, RELEASE.md) and execute git tagging operations via the herald agent.
  • Sanitization: The skill contains no instructions for filtering or validating the output from the audit and test tools before it is processed by the review logic.
  • [COMMAND_EXECUTION]: The orchestration logic instructs sub-agents to perform several sensitive shell operations associated with the release process.
  • Evidence: Instructions in SKILL.md for Phase 1 and Phase 4 involve executing npm audit, pip audit, and git commands such as Tag commit.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:10 PM
Security Audit — agent-trust-hub — release