kmp-release

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill leverages git-cliff to automate changelog generation from git commit history, creating a surface where instructions embedded in commit messages could influence downstream processes or AI agents reading the published release notes.
  • Ingestion points: Git commit history processed by git-cliff as configured in SKILL.md and executed in scripts/publish.sh.
  • Boundary markers: Absent; the cliff.toml configuration in SKILL.md interpolates commit messages into the generated changelog without specific delimiters or "ignore previous instructions" warnings.
  • Capability inventory: File system write operations (CHANGELOG.md), GitHub Release creation via gh release create, and git tagging/pushing via the shell script in SKILL.md.
  • Sanitization: Absent; commit messages are parsed and formatted using the upper_first filter but are not escaped or sanitized to prevent the propagation of malicious prompt injection content into the final release artifacts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 11:35 PM
Security Audit — agent-trust-hub — kmp-release