Back to skill

Security audit

Changelog Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a focused changelog-writing helper with no executable code, persistence, credential use, or unrelated authority.

Installers should expect this skill to help rewrite supplied commit or release information into polished changelog text. Review generated changelog entries for accuracy, especially breaking changes and migration notes, but the artifact itself does not show risky behavior.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.