release-easydict

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands by invoking the GitHub CLI (gh) through Python's subprocess module. These commands are used to view releases, edit release titles, fetch pull request details, and manage issue comments and status.
  • [INDIRECT_PROMPT_INJECTION]: The skill parses and acts upon data retrieved from external, potentially attacker-controlled sources, specifically GitHub PR bodies, commit messages, and issue comments.
  • Ingestion points: The scripts/release_issues.py script fetches PR descriptions and issue comments via the GitHub API to identify linked issues and determine if they should be closed.
  • Boundary markers: The skill uses specific Markdown headings (e.g., ## 关联 Issue / Linked Issues) and regex patterns for issue references, but these do not prevent an attacker from embedding instructions within the text that might influence the agent's logic during the planning phase.
  • Capability inventory: The skill possesses the capability to modify GitHub repository state, including editing release metadata, posting comments on issues, and closing issues.
  • Sanitization: The scripts/release_content.py script implements validation for release titles, checking for length limits and restricting characters to the Latin alphabet to prevent visual spoofing or long-string attacks. Issue numbers are parsed and cast to integers in scripts/release_issues.py before being used in API calls.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:09 PM
Security Audit — agent-trust-hub — release-easydict