product-changelog

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill documents and encourages the use of the belt CLI tool for logging in and executing remote applications like falai/flux-dev-lora and bytedance/seededit-3-0-i2i. These operations are consistent with the skill's stated purpose of assisting in changelog documentation and visual asset generation.
  • [EXTERNAL_DOWNLOADS]: The skill provides installation instructions pointing to a public GitHub repository (inference-sh/skills) and utilizes npx to add external skills from the belt-sh organization. These sources are related to the platform's standard ecosystem.
  • [PROMPT_INJECTION]: The skill describes a workflow that ingests untrusted project data (e.g., PR bodies, commit messages) to generate changelog entries. This constitutes an indirect prompt injection surface.
  • Ingestion points: Internal development language provided for rewriting into user-facing entries.
  • Boundary markers: None present in the provided instructions to delimit external content.
  • Capability inventory: Execution of shell commands via the belt tool (SKILL.md).
  • Sanitization: No explicit sanitization or filtering of input data is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 05:02 AM
Security Audit — agent-trust-hub — product-changelog