bump
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill identifies and executes build, test, and linting commands discovered dynamically from project manifest files such as
package.json,composer.json,Makefile, andCargo.toml. - Evidence: Steps 4 and 5 in
SKILL.mdinstruct the agent to detect available scripts (e.g.,npm run build,make test,cargo clippy) and execute them automatically. - Risk: If the repository being processed is malicious or compromised, it can define arbitrary shell commands in these manifests which the agent will execute with the user's local privileges.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted commit history to generate changelog entries, creating an attack surface where malicious commit messages could influence the agent's behavior.
- Ingestion points: The skill reads commit subjects via
git log <last-tag>..HEAD --oneline --no-mergesin Step 0 ofSKILL.md. - Boundary markers: Absent. There are no instructions to use delimiters or to treat the commit subjects as strictly untrusted data that should not be followed as instructions.
- Capability inventory: The skill has broad capabilities including shell command execution (
npm,cargo,make,git) and file system write access for manifest and changelog updates. - Sanitization: Absent. The skill instructions specify filtering for "noise" (like
chore:orci:prefixes) and cosmetic formatting (capitalization), but do not include security-focused sanitization to prevent the AI from obeying instructions embedded within the commit messages.
Audit Metadata