release-easydict
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes shell commands by invoking the GitHub CLI (
gh) through Python'ssubprocessmodule. These commands are used to view releases, edit release titles, fetch pull request details, and manage issue comments and status. - [INDIRECT_PROMPT_INJECTION]: The skill parses and acts upon data retrieved from external, potentially attacker-controlled sources, specifically GitHub PR bodies, commit messages, and issue comments.
- Ingestion points: The
scripts/release_issues.pyscript fetches PR descriptions and issue comments via the GitHub API to identify linked issues and determine if they should be closed. - Boundary markers: The skill uses specific Markdown headings (e.g.,
## 关联 Issue / Linked Issues) and regex patterns for issue references, but these do not prevent an attacker from embedding instructions within the text that might influence the agent's logic during the planning phase. - Capability inventory: The skill possesses the capability to modify GitHub repository state, including editing release metadata, posting comments on issues, and closing issues.
- Sanitization: The
scripts/release_content.pyscript implements validation for release titles, checking for length limits and restricting characters to the Latin alphabet to prevent visual spoofing or long-string attacks. Issue numbers are parsed and cast to integers inscripts/release_issues.pybefore being used in API calls.
Audit Metadata