setup-phatblat-skills
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
git remote -vandgit tag --listto explore repository state. These are standard, non-destructive commands used for legitimate project configuration. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the local repository, including
CHANGELOG.md, package manifests, and release configuration files. While this creates a surface for indirect prompt injection, the skill's logic is constrained to identifying specific project patterns and the risk is minimal given the specialized scope. - Ingestion points:
CHANGELOG.md,.releaserc*,.changeset/,.changes/,release-plz.toml,git tagoutput, and package manifests. - Boundary markers: Absent; the skill relies on searching for specific structure or marker lines within files.
- Capability inventory: File system write access to
AGENTS.mdandCLAUDE.md; shell execution forgitcommands. - Sanitization: None explicitly mentioned; the skill generates documentation based on pre-defined templates.
Audit Metadata