product-changelog

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is primarily instructional documentation designed to assist users in writing effective product updates and changelogs. It contains no malicious logic, obfuscation, or persistence mechanisms.
  • [COMMAND_EXECUTION]: The documentation includes bash snippets for using the belt CLI tool, such as belt login and belt app run. These are intended as user-executed commands to facilitate the generation of product visuals (like analytics charts or screenshots) and are consistent with the tool's intended purpose.
  • [EXTERNAL_DOWNLOADS]: The skill references a GitHub URL for installing CLI tools and uses npx commands to add related skills. These external references target repositories within the vendor's ecosystem and are standard for the skill's setup process.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides an example of using a browser-based tool to take screenshots of live URLs. While this represents a potential surface for processing untrusted data, the context is limited to capturing visual documentation for release notes as explicitly requested by the user, minimizing the risk of autonomous exploitation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 02:19 PM
Security Audit — agent-trust-hub — product-changelog