setup-phatblat-skills

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses git remote -v and git tag --list to explore repository state. These are standard, non-destructive commands used for legitimate project configuration.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the local repository, including CHANGELOG.md, package manifests, and release configuration files. While this creates a surface for indirect prompt injection, the skill's logic is constrained to identifying specific project patterns and the risk is minimal given the specialized scope.
  • Ingestion points: CHANGELOG.md, .releaserc*, .changeset/, .changes/, release-plz.toml, git tag output, and package manifests.
  • Boundary markers: Absent; the skill relies on searching for specific structure or marker lines within files.
  • Capability inventory: File system write access to AGENTS.md and CLAUDE.md; shell execution for git commands.
  • Sanitization: None explicitly mentioned; the skill generates documentation based on pre-defined templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 07:21 PM
Security Audit — agent-trust-hub — setup-phatblat-skills