prepare-release-notes
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data sourced from Git commit messages and GitHub PR titles/bodies to generate release highlights.
- Ingestion points: The agent reads the output of
git logandgh pr list(SKILL.md Step 1) to extract information for drafting highlights. - Boundary markers: The instructions do not provide delimiters or "ignore embedded instructions" warnings to prevent the agent from following malicious commands hidden in commit history.
- Capability inventory: The skill has shell execution capabilities (running
git,gh, andbasename) and file system access (writing to/tmp). - Sanitization: The skill lacks logic to sanitize or filter external content before interpolating it into the drafting prompt.
- [COMMAND_EXECUTION]: The skill executes local shell commands to inspect the repository environment and history.
- Evidence: Instructions in SKILL.md specify the execution of
git describe,git log,gh pr list,git rev-parse, andbasenameto gather data and determine the repository name.
Audit Metadata