prepare-release-notes

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses local shell commands to interact with the repository and gather data.
  • Evidence: Executes git describe, git log, and gh pr list to identify changes since the last tag.
  • Context: These are standard operations for a development-focused skill and are used solely for information retrieval.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external, potentially untrusted sources which could influence the agent's output.
  • Ingestion points: Merged pull request titles and bodies are retrieved via gh pr list and git log.
  • Boundary markers: The skill lack explicit delimiters or instructions to ignore embedded commands within the PR content.
  • Capability inventory: The agent can execute shell commands (git, gh) and write files to the /tmp/ directory.
  • Sanitization: There is no evidence of filtering or sanitization performed on the PR data before it is processed into the release notes draft.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 09:50 PM
Security Audit — agent-trust-hub — prepare-release-notes