bump-release
Pass
Audited by Gen Agent Trust Hub on Apr 9, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [SAFE]: The skill performs expected tasks for a release management tool. No malicious code, obfuscation, or unauthorized data access was detected.\n- [COMMAND_EXECUTION]: The skill invokes
gitfor status, committing, and tagging, and optionally runsjust full-writeto format configuration files. These actions are transparently documented and align with the skill's stated purpose.\n- [PROMPT_INJECTION]: The skill does not contain instructions that attempt to bypass AI safety protocols. While it processes git logs which are externally controlled, it treats them as data for the changelog rather than instructions to execute. It contains a surface for indirect prompt injection via git logs (Ingestion: git history/PR titles; Boundary markers: none; Capability: file-write, git-tag; Sanitization: none), but this is inherent to the tool's primary purpose.
Audit Metadata