output-github-release

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided career assets and release notes which are external, untrusted content.
  • The instructions explicitly mandate treating all assets and release notes as untrusted content.
  • Security measures include verifying local paths, filenames, sizes, media types, and SHA-256 digests before any external interaction.
  • It implements a disclosure policy check for personal-contact fields to prevent accidental exposure of PII (Personally Identifiable Information).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:16 PM
Security Audit — agent-trust-hub — output-github-release