changelog
Pass
Audited by Gen Agent Trust Hub on Mar 28, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
Bashtool to executegitcommands such asgit rev-parseandgit log. These operations are used to verify repository status and extract commit history for changelog generation.- [DYNAMIC_CONTEXT_INJECTION]: The skill uses dynamic context injection (the!command syntax) in its YAML frontmatter to rungit logandgit tagat load time. This provides the agent with immediate repository context, which is a legitimate use case for a developer-oriented skill.- [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted data from git commit messages and local project documentation. - Ingestion points: Data is read from
git logoutput and files withinproduction/sprints/anddesign/gdd/. - Boundary markers: The skill does not implement specific delimiters or 'ignore' instructions for the ingested content.
- Capability inventory: The skill is permitted to use
Read,Glob,Grep, andBashtools. - Sanitization: There is no evidence of sanitization or filtering of the content retrieved from commits or local files.
Audit Metadata