release-bumper

Pass

Audited by Gen Agent Trust Hub on Oct 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs legitimate repository maintenance tasks such as version bumping and git tagging. All operations are scoped to the local repository, and external writes (e.g., GitHub releases) are designed to be user-authorized recommendations or commands.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from repository files (package.json, git diffs). However, it includes explicit instructions for the agent to disregard non-authoritative hints and prioritize actual diff content, reducing the risk of being misled by malicious metadata or filenames.
  • Ingestion points: Reads package.json, pnpm-workspace.yaml, and git history/diffs in scripts/plan-release.ts.
  • Boundary markers: The instructions explicitly warn the agent: 'Never use [changeHints] to decide release relevance' and 'Filenames never decide this'.
  • Capability inventory: File system writes (manifests, changelogs), git commit, git tag, and recommendation of gh release commands.
  • Sanitization: Subprocess calls in TypeScript and Python scripts utilize argument arrays (execFileSync, subprocess.run), preventing shell injection. Data parsing is handled via standard JSON and regex libraries.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 10, 2026, 06:04 AM