release
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from git commit history and GitHub Pull Request metadata which could potentially contain malicious instructions intended to influence the agent.
- Ingestion points: Commit messages (Phase 2) and Pull Request metadata (Phase 3) as described in SKILL.md.
- Boundary markers: Present. The skill includes specific instructions in the "External Side Effects" section of SKILL.md directing the agent to treat these inputs as untrusted and explicitly ignore any embedded instructions.
- Capability inventory: Shell execution of
gitandghtools and modification ofCHANGELOG.mdas specified in SKILL.md. - Sanitization: Present. The agent is instructed to summarize content rather than reproducing it verbatim and to redact any secret-like values found in the untrusted inputs.
Audit Metadata