release-sync
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from local project files to update external knowledge systems. This creates a potential surface where an attacker who can modify project documentation could influence the agent's behavior during the sync process. \n
- Ingestion points: Content is read from
CHANGELOG.md,CLAUDE.md, andsrc/hooks/README.mdin Step 1. \n - Boundary markers: The skill does not employ explicit delimiters or instructions to the agent to ignore embedded prompts within the ingested text. \n
- Capability inventory: The skill has the capability to perform network egress via the
mcp__notebooklm-mcp__source_addandmcp__hq-content__knowledge_ingesttools. \n - Sanitization: No content validation or sanitization is performed on the ingested file data before it is transmitted to the external services.
Audit Metadata