release-tweets

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The instructions direct the agent to use local shell utilities for its core functionality. This includes using pbcopy on macOS to transfer text to the system clipboard and using the tools bird and xurl to post updates to X.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from changelogs and GitHub releases, creating a surface for indirect prompt injection attacks.
  • Ingestion points: Content is read from project files such as CHANGELOG.md and remote GitHub release notes.
  • Boundary markers: No delimiters or instructions are provided to distinguish between data and commands within the ingested text.
  • Capability inventory: The skill possesses shell command execution and file reading capabilities.
  • Sanitization: The skill does not implement sanitization or validation of the ingested text to prevent instruction injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 11:27 PM
Security Audit — agent-trust-hub — release-tweets