release-notes
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is authored by 'tw93' for the 'tw93/Mole' repository and performs standard development operations within that context. No malicious patterns were identified.
- [COMMAND_EXECUTION]: The workflow executes local validation tools including
go test,make build, and./scripts/test.sh. It also uses a helper script,scripts/post-reactions.sh, to interact with the repository's release API via the GitHub CLI. - [EXTERNAL_DOWNLOADS]: The release template references a logo image hosted at
https://cdn.tw93.fun/pic/cole.png, a domain associated with the skill's author. - [PROMPT_INJECTION]: The skill analyzes external commit data from
git log. Ingestion points: Commit bodies and release metadata. Boundary markers: None present to distinguish data from instructions. Capability inventory: GitHub CLI release editing and reaction posting. Sanitization: None detected for commit data interpolation.
Audit Metadata