product-changelog
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill documents and encourages the use of the
beltCLI tool for logging in and executing remote applications likefalai/flux-dev-loraandbytedance/seededit-3-0-i2i. These operations are consistent with the skill's stated purpose of assisting in changelog documentation and visual asset generation. - [EXTERNAL_DOWNLOADS]: The skill provides installation instructions pointing to a public GitHub repository (
inference-sh/skills) and utilizesnpxto add external skills from thebelt-shorganization. These sources are related to the platform's standard ecosystem. - [PROMPT_INJECTION]: The skill describes a workflow that ingests untrusted project data (e.g., PR bodies, commit messages) to generate changelog entries. This constitutes an indirect prompt injection surface.
- Ingestion points: Internal development language provided for rewriting into user-facing entries.
- Boundary markers: None present in the provided instructions to delimit external content.
- Capability inventory: Execution of shell commands via the
belttool (SKILL.md). - Sanitization: No explicit sanitization or filtering of input data is described.
Audit Metadata