release-sync

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from local project files to update external knowledge systems. This creates a potential surface where an attacker who can modify project documentation could influence the agent's behavior during the sync process. \n
  • Ingestion points: Content is read from CHANGELOG.md, CLAUDE.md, and src/hooks/README.md in Step 1. \n
  • Boundary markers: The skill does not employ explicit delimiters or instructions to the agent to ignore embedded prompts within the ingested text. \n
  • Capability inventory: The skill has the capability to perform network egress via the mcp__notebooklm-mcp__source_add and mcp__hq-content__knowledge_ingest tools. \n
  • Sanitization: No content validation or sanitization is performed on the ingested file data before it is transmitted to the external services.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 02:15 AM
Security Audit — agent-trust-hub — release-sync