release-and-changeset-best-practices

Pass

Audited by Gen Agent Trust Hub on Apr 30, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes local scripts (e.g., scripts/check-catalog-changeset.ts) and common development tools like pnpm and git to automate release and issue-tracking tasks. These operations are expected within a software development context.
  • [PROMPT_INJECTION]: The skill processes content from GitHub issues, which serves as an ingestion point for untrusted data. This establishes an indirect prompt injection surface. The risk is mitigated by the workflow's requirements for manual verification steps, such as establishing a minimal reproduction in a git worktree and running regression tests.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 30, 2026, 07:41 AM