team-release
Pass
Audited by Gen Agent Trust Hub on Mar 28, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by interpolating untrusted repository data into subagent contexts.
- Ingestion points: The agent reads project-specific data including milestone acceptance criteria, scope items, release checklists, and bug reports using the
Read,Glob, andGreptools. - Boundary markers: The instructions do not define clear delimiters or instruct subagents to ignore potential instructions embedded within the processed documentation or data files.
- Capability inventory: The skill possesses high-privilege capabilities including the
Bashtool for shell execution,Write/Editfor file modification, and theTasktool for spawning further subagents, creating a significant impact if the agent is manipulated. - Sanitization: There is no evidence of sanitization or validation for the data ingested from the repository before it is used to influence the release pipeline or command execution.
Audit Metadata