github-release-management
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted content from external contributors which could contain malicious instructions designed to manipulate the AI during the release process.
- Ingestion points: The skill fetches commit messages and pull request metadata via
gh apiandgh pr listcommands as shown in theSKILL.mdworkflows. - Boundary markers: There are no explicit delimiters or instructions to the AI agent to ignore potentially malicious embedded directives in the fetched text.
- Capability inventory: The skill leverages high-privilege capabilities including shell command execution (
Bash) and file writing (Write) which could be misused if an injection is successful. - Sanitization: No explicit sanitization or filtering of the external commit and PR data is performed before it is used to generate release artifacts.
- [COMMAND_EXECUTION]: The skill makes extensive use of the
Bashtool to executeghCLI commands and Node.js scripts for repository management, building artifacts, and coordinating deployments. - [EXTERNAL_DOWNLOADS]: The skill utilizes
npxto dynamically retrieve and execute theclaude-flowutility and its associated swarm modules from the npm registry during the release pipeline.
Audit Metadata