team-release

Pass

Audited by Gen Agent Trust Hub on Mar 28, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by interpolating untrusted repository data into subagent contexts.
  • Ingestion points: The agent reads project-specific data including milestone acceptance criteria, scope items, release checklists, and bug reports using the Read, Glob, and Grep tools.
  • Boundary markers: The instructions do not define clear delimiters or instruct subagents to ignore potential instructions embedded within the processed documentation or data files.
  • Capability inventory: The skill possesses high-privilege capabilities including the Bash tool for shell execution, Write/Edit for file modification, and the Task tool for spawning further subagents, creating a significant impact if the agent is manipulated.
  • Sanitization: There is no evidence of sanitization or validation for the data ingested from the repository before it is used to influence the release pipeline or command execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 28, 2026, 12:11 PM
Security Audit — agent-trust-hub — team-release