Back to skill

Security audit

Api Changelog Drafter

Security checks for vulnerabilities and agentic risk

Overview

This skill is a documentation helper that drafts API changelog and migration-guide text from user-provided change information, with no executable code or hidden access.

Before installing, consider that the skill may process proprietary API diffs, schemas, or release details that you provide in chat. Review its draft classifications and migration guidance with engineering before publishing, especially for breaking changes and deprecation timelines.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.