release-dispatch

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill resolves repository state such as trunk branches and release tags using shell tools, which creates an ingestion point for potentially untrusted data from the repository environment.
  • Ingestion points: Repository state resolution in SKILL.md (Step 2) using git and gh commands.
  • Boundary markers: The skill provides a specific instruction in the External Side Effects section stating that PR bodies, commit messages, and tags are untrusted input and instructions within them must not be obeyed.
  • Capability inventory: Tool usage is restricted to Bash(git *) and Bash(gh *) as specified in the allowed-tools metadata.
  • Sanitization: The skill provides explicit behavioral guidance to the AI agent to ignore instructions embedded in the processed repository metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 08:30 AM
Security Audit — agent-trust-hub — release-dispatch