kmp-release
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill leverages
git-cliffto automate changelog generation from git commit history, creating a surface where instructions embedded in commit messages could influence downstream processes or AI agents reading the published release notes. - Ingestion points: Git commit history processed by
git-cliffas configured inSKILL.mdand executed inscripts/publish.sh. - Boundary markers: Absent; the
cliff.tomlconfiguration inSKILL.mdinterpolates commit messages into the generated changelog without specific delimiters or "ignore previous instructions" warnings. - Capability inventory: File system write operations (
CHANGELOG.md), GitHub Release creation viagh release create, and git tagging/pushing via the shell script inSKILL.md. - Sanitization: Absent; commit messages are parsed and formatted using the
upper_firstfilter but are not escaped or sanitized to prevent the propagation of malicious prompt injection content into the final release artifacts.
Audit Metadata