release-notes-writer

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection through its data processing workflow.
  • Ingestion points: The agent is instructed to read 'source specs' and 'completed tickets' from the local environment (SKILL.md).
  • Boundary markers: The instructions lack specific delimiters or boundary markers to distinguish between data and instructions within the ingested content.
  • Capability inventory: The agent has capabilities to read files (specs/tickets) and write files (release notes).
  • Sanitization: There is no requirement for the agent to sanitize, validate, or escape the content of the ingested files before using them to generate notes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 06:28 AM
Security Audit — agent-trust-hub — release-notes-writer