release-and-store-shipping
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill enforces security best practices by requiring that signing keys, keystores, and API tokens are never committed to the repository, instead mandating their injection from a secure secret store at build time.
- [SAFE]: The included utility scripts (
check-release-hygiene.shandcheck-ipa-slices.sh) perform local static analysis of project files and build artifacts using standard system tools (grep, awk, lipo, otool) to prevent common release mistakes like debug-signed binaries or simulator-targeted builds without initiating network connections. - [SAFE]: All external documentation references target trusted organizations and well-known services (Google, Apple, Flutter) and are used neutrally for technical guidance.
- [INDIRECT_PROMPT_INJECTION]: The skill audits manifest files which may contain untrusted data from transitive dependencies, representing a potential indirect prompt injection surface. This is mitigated by the skill's instructions for the agent to diff the merged output against committed, expected baselines.
- Ingestion points: Merged Android manifests, iOS property lists (
Info.plist), and privacy manifests (PrivacyInfo.xcprivacy) are read during the release ritual to verify project state. - Boundary markers: The instructions mandate comparing the merged build outputs against a committed 'expected' permission set, providing a validation boundary against unauthorized changes.
- Capability inventory: The skill utilizes local shell execution for auditing (grep, awk, lipo, otool) and standard Flutter build commands.
- Sanitization: The audit process focuses on identifying and stripping unexpected permissions or declarations via the
tools:node="remove"manifest attribute.
Audit Metadata