NYC

prepare-changelog

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [No Code] (SAFE): The skill consists entirely of markdown documentation and metadata. There are no executable scripts, binaries, or active code components provided within the skill files.
  • [Prompt Injection] (SAFE): Although the skill describes a workflow for processing untrusted data from git logs and GitHub PRs (an Indirect Prompt Injection surface), this activity is inherent to the primary purpose of changelog generation and is conducted through standard informational commands. * Ingestion points: Git commit history and GitHub Pull Request metadata via git log and gh pr view commands. * Boundary markers: None specified in the formatting guidelines. * Capability inventory: Limited to informational CLI tools (git, gh, wc) used for data retrieval. * Sanitization: None specified for the content retrieved from commit messages or PR descriptions.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:30 PM