release-plugin-package
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to perform Git operations and interact with the GitHub CLI.
- Evidence: The instructions specify using
gitfor branch creation, committing, and pushing changes, as well as using theghCLI (or Codex GitHub connector) to create pull requests. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a standard attack surface by processing external data from Git history and pull requests.
- Ingestion points:
SKILL.mdinstructs the agent to identify changes using "commits and merged PRs since the resolved baseline" to generate changelogs. - Boundary markers: There are no explicit delimiters or boundary instructions provided to the agent to treat external commit messages as untrusted data.
- Capability inventory: The skill has the ability to write to files (
package.json,CHANGELOG.md), commit to the repository, and create remote pull requests viagh. - Sanitization: The instructions lack specific sanitization requirements for text extracted from Git history before it is interpolated into the changelog or pull request descriptions.
Audit Metadata