bump-rspack-swc

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources which could contain malicious instructions.
  • Ingestion points: The agent is instructed to read PR titles, bodies, and commit messages from the swc-project/swc GitHub repository to build a changelog.
  • Boundary markers: There are no explicit delimiters or specific instructions to ignore embedded commands within the fetched external PR text.
  • Capability inventory: The skill has the ability to execute shell commands (cargo, pnpm), commit code, and push to a remote repository.
  • Sanitization: There is no mention of sanitizing or escaping the upstream content before it is processed or included in the final PR description.
  • [COMMAND_EXECUTION]: The skill executes local development commands to regenerate code and validate changes.
  • Evidence: The skill runs cargo codegen to update generated files and pnpm run build:binding:dev to verify the build process.
  • [EXTERNAL_DOWNLOADS]: The skill connects to well-known external services to retrieve versioning and release information.
  • Evidence: Fetches release metadata from crates.io and retrieves tag/comparison data from the official swc-project/swc GitHub repository.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 04:51 PM
Security Audit — agent-trust-hub — bump-rspack-swc