changelog-generator

Fail

Audited by Gen Agent Trust Hub on Feb 16, 2026

Risk Level: HIGHPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION] (HIGH): Vulnerable to Indirect Prompt Injection via git commit messages.\n
  • Ingestion points: Git commit history and user-provided style guide files (e.g., CHANGELOG_STYLE.md).\n
  • Boundary markers: Absent; no delimiting or instruction-shielding is implemented.\n
  • Capability inventory: File writing (saving results to CHANGELOG.md) and git command execution.\n
  • Sanitization: Absent; commit content is treated as trusted data.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Feb 16, 2026, 02:29 PM