prepare-release-notes
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses local shell commands to interact with the repository and gather data.
- Evidence: Executes
git describe,git log, andgh pr listto identify changes since the last tag. - Context: These are standard operations for a development-focused skill and are used solely for information retrieval.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external, potentially untrusted sources which could influence the agent's output.
- Ingestion points: Merged pull request titles and bodies are retrieved via
gh pr listandgit log. - Boundary markers: The skill lack explicit delimiters or instructions to ignore embedded commands within the PR content.
- Capability inventory: The agent can execute shell commands (
git,gh) and write files to the/tmp/directory. - Sanitization: There is no evidence of filtering or sanitization performed on the PR data before it is processed into the release notes draft.
Audit Metadata