release-pr-gates
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted data from external sources such as pull request metadata and CI/CD logs. Evidence Chain: 1. Ingestion points: The skill reads PR state via
gh pr list, commit summaries viagit log, and CI workflow logs viagh run view. 2. Boundary markers: The instructions explicitly state to treat PR metadata, commit messages, and CI logs as untrusted text and warn the agent not to follow instructions embedded in these fields. 3. Capability inventory: The skill has permissions to write to the repository (tags/releases) and execute local scripts. 4. Sanitization: It instructs the agent to redact secret-like values before summarizing logs or commit messages. - [COMMAND_EXECUTION]: The skill executes locally defined scripts via
npm runandbun run(e.g., format, lint, type-check). This involves executing commands defined within the target repository'spackage.jsonfile. - [EXTERNAL_DOWNLOADS]: The skill uses
bunxandnpmto run development tools such as Biome, Turbo, and TypeScript. These tools and their registries are well-known development services, and the downloads are performed within the scope of standard project maintenance.
Audit Metadata