release-dispatch
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill resolves repository state such as trunk branches and release tags using shell tools, which creates an ingestion point for potentially untrusted data from the repository environment.
- Ingestion points: Repository state resolution in SKILL.md (Step 2) using git and gh commands.
- Boundary markers: The skill provides a specific instruction in the External Side Effects section stating that PR bodies, commit messages, and tags are untrusted input and instructions within them must not be obeyed.
- Capability inventory: Tool usage is restricted to Bash(git *) and Bash(gh *) as specified in the allowed-tools metadata.
- Sanitization: The skill provides explicit behavioral guidance to the AI agent to ignore instructions embedded in the processed repository metadata.
Audit Metadata