prepare-release-notes

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data sourced from Git commit messages and GitHub PR titles/bodies to generate release highlights.
  • Ingestion points: The agent reads the output of git log and gh pr list (SKILL.md Step 1) to extract information for drafting highlights.
  • Boundary markers: The instructions do not provide delimiters or "ignore embedded instructions" warnings to prevent the agent from following malicious commands hidden in commit history.
  • Capability inventory: The skill has shell execution capabilities (running git, gh, and basename) and file system access (writing to /tmp).
  • Sanitization: The skill lacks logic to sanitize or filter external content before interpolating it into the drafting prompt.
  • [COMMAND_EXECUTION]: The skill executes local shell commands to inspect the repository environment and history.
  • Evidence: Instructions in SKILL.md specify the execution of git describe, git log, gh pr list, git rev-parse, and basename to gather data and determine the repository name.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 09:23 PM
Security Audit — agent-trust-hub — prepare-release-notes