rspack-release-pr

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill performs extensive shell operations to manage the release lifecycle. This includes worktree cleanup (git clean), dependency management (pnpm install), version bumping via a local script (./x version), and pull request creation using the GitHub CLI (gh pr create). While these are standard for a release tool, they grant the agent broad control over the local environment and remote repository.
  • [EXTERNAL_DOWNLOADS]: The workflow triggers pnpm install, which fetches and installs dependencies from the NPM registry. This is a routine part of the Node.js release process but represents an external dependency ingestion point.
  • [INDIRECT_PROMPT_INJECTION]: The skill accepts version types (e.g., major, minor) and pre-release tags (e.g., alpha, beta) from user input and interpolates them directly into shell command arguments for the ./x script. Without strict validation, this could be exploited to perform command injection.
  • Ingestion points: User-specified version bump types and pre-release tags in SKILL.md.
  • Boundary markers: Absent. The skill instructions do not define delimiters or specific 'ignore' instructions for the interpolated user values.
  • Capability inventory: The skill possesses the capability to execute arbitrary shell commands, write to the file system, and interact with the GitHub API/network.
  • Sanitization: Absent. There is no evidence of input validation or escaping to ensure the user input matches the expected enumeration of release types before execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 04:51 PM
Security Audit — agent-trust-hub — rspack-release-pr