keep-a-changelog
Pass
Audited by Gen Agent Trust Hub on Apr 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill uses standard local system commands such as
git loganddateto retrieve information necessary for its primary task of updating a changelog. - [SAFE]: All operations are performed on local project files (
CHANGELOG.md) and the local git history. No network requests to external domains or unauthorized file access patterns were detected. - [SAFE]: While the skill ingests external data in the form of git commit messages and existing changelog content, its capabilities are strictly scoped to generating formatted documentation. The risk of indirect prompt injection from commit messages is minimal and inherent to the intended functionality of maintaining a release history.
Audit Metadata