release-plugin-package

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to perform Git operations and interact with the GitHub CLI.
  • Evidence: The instructions specify using git for branch creation, committing, and pushing changes, as well as using the gh CLI (or Codex GitHub connector) to create pull requests.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a standard attack surface by processing external data from Git history and pull requests.
  • Ingestion points: SKILL.md instructs the agent to identify changes using "commits and merged PRs since the resolved baseline" to generate changelogs.
  • Boundary markers: There are no explicit delimiters or boundary instructions provided to the agent to treat external commit messages as untrusted data.
  • Capability inventory: The skill has the ability to write to files (package.json, CHANGELOG.md), commit to the repository, and create remote pull requests via gh.
  • Sanitization: The instructions lack specific sanitization requirements for text extracted from Git history before it is interpolated into the changelog or pull request descriptions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 04:52 PM
Security Audit — agent-trust-hub — release-plugin-package