Flagged by auditors
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
passThis skill automates software release workflows by integrating GitHub CLI with a vendor-specific orchestration tool. It is susceptible to indirect prompt injection because it ingests untrusted data from commit messages and pull request descriptions without sanitization, which could allow an attacker with repository access to influence the release process or generated changelogs.
Socket
warn1 alert: gptSecurity
Snyk
warnRisk: MEDIUM · No issues
Runlayer
fail1/1 file flagged
ZeroLeaks
passScore: 93/100 · 2 sections analyzed