release-notes-writer
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection through its data processing workflow.
- Ingestion points: The agent is instructed to read 'source specs' and 'completed tickets' from the local environment (SKILL.md).
- Boundary markers: The instructions lack specific delimiters or boundary markers to distinguish between data and instructions within the ingested content.
- Capability inventory: The agent has capabilities to read files (specs/tickets) and write files (release notes).
- Sanitization: There is no requirement for the agent to sanitize, validate, or escape the content of the ingested files before using them to generate notes.
Audit Metadata