rspack-release-pr
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill performs extensive shell operations to manage the release lifecycle. This includes worktree cleanup (
git clean), dependency management (pnpm install), version bumping via a local script (./x version), and pull request creation using the GitHub CLI (gh pr create). While these are standard for a release tool, they grant the agent broad control over the local environment and remote repository. - [EXTERNAL_DOWNLOADS]: The workflow triggers
pnpm install, which fetches and installs dependencies from the NPM registry. This is a routine part of the Node.js release process but represents an external dependency ingestion point. - [INDIRECT_PROMPT_INJECTION]: The skill accepts version types (e.g., major, minor) and pre-release tags (e.g., alpha, beta) from user input and interpolates them directly into shell command arguments for the
./xscript. Without strict validation, this could be exploited to perform command injection. - Ingestion points: User-specified version bump types and pre-release tags in SKILL.md.
- Boundary markers: Absent. The skill instructions do not define delimiters or specific 'ignore' instructions for the interpolated user values.
- Capability inventory: The skill possesses the capability to execute arbitrary shell commands, write to the file system, and interact with the GitHub API/network.
- Sanitization: Absent. There is no evidence of input validation or escaping to ensure the user input matches the expected enumeration of release types before execution.
Audit Metadata