github-release-management

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted content from external contributors which could contain malicious instructions designed to manipulate the AI during the release process.
  • Ingestion points: The skill fetches commit messages and pull request metadata via gh api and gh pr list commands as shown in the SKILL.md workflows.
  • Boundary markers: There are no explicit delimiters or instructions to the AI agent to ignore potentially malicious embedded directives in the fetched text.
  • Capability inventory: The skill leverages high-privilege capabilities including shell command execution (Bash) and file writing (Write) which could be misused if an injection is successful.
  • Sanitization: No explicit sanitization or filtering of the external commit and PR data is performed before it is used to generate release artifacts.
  • [COMMAND_EXECUTION]: The skill makes extensive use of the Bash tool to execute gh CLI commands and Node.js scripts for repository management, building artifacts, and coordinating deployments.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes npx to dynamically retrieve and execute the claude-flow utility and its associated swarm modules from the npm registry during the release pipeline.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:38 AM
Security Audit — agent-trust-hub — github-release-management