release

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill discovers and executes various commands found within the repository, including identified 'test gate' commands, release scripts (e.g., scripts/release.*), and package registry publish commands (npm publish, twine upload).
  • [DYNAMIC_EXECUTION]: The skill implements a workflow that involves identifying arbitrary command strings from CI configurations (GitHub Actions, CircleCI, etc.) and Makefiles, then executing them locally during the release process.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection through repository metadata and history.
  • Ingestion points: Reads repository files such as CHANGELOG.md, CI workflow files, and analyzes output from git log to generate release notes.
  • Boundary markers: The instructions do not specify explicit delimiters or 'ignore' instructions when processing external data from the repository files or logs.
  • Capability inventory: The skill can write files to the project directory (.omc/RELEASE_RULE.md, .gitignore, CI workflows) and execute discovered shell commands via subprocesses.
  • Sanitization: No explicit sanitization or validation logic is defined for content extracted from the repository before it is processed or used in decision-making.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:35 PM
Security Audit — agent-trust-hub — release