release-pr-gates

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted data from external sources such as pull request metadata and CI/CD logs. Evidence Chain: 1. Ingestion points: The skill reads PR state via gh pr list, commit summaries via git log, and CI workflow logs via gh run view. 2. Boundary markers: The instructions explicitly state to treat PR metadata, commit messages, and CI logs as untrusted text and warn the agent not to follow instructions embedded in these fields. 3. Capability inventory: The skill has permissions to write to the repository (tags/releases) and execute local scripts. 4. Sanitization: It instructs the agent to redact secret-like values before summarizing logs or commit messages.
  • [COMMAND_EXECUTION]: The skill executes locally defined scripts via npm run and bun run (e.g., format, lint, type-check). This involves executing commands defined within the target repository's package.json file.
  • [EXTERNAL_DOWNLOADS]: The skill uses bunx and npm to run development tools such as Biome, Turbo, and TypeScript. These tools and their registries are well-known development services, and the downloads are performed within the scope of standard project maintenance.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 05:10 AM
Security Audit — agent-trust-hub — release-pr-gates