document-release
What this skill does
Post-ship documentation update. Reads all project docs, cross-references the diff, updates README/ARCHITECTURE/CONTRIBUTING/CLAUDE.md to match what shipped, polishes CHANGELOG voice, cleans up TODOS,
github/leoyeai - Command Injection - 2.1k stars
Threat analysis
Skill info
pkg:github/LeoYeAI/openclaw-master-skills@e5199b5?skill=document-releaseAssessments (3)
Command Injection
Command Injection via local-llm-review
SKILL.md
The skill executes shell commands with untrusted input, such as `~/.claude/skills/gstack/bin/gstack-update-check` and `git branch --show-current`. These commands could be manipulated by an attacker toEnvironment Manipulation
Environment Manipulation via local-llm-review
SKILL.md
The skill uses environment variables such as `PPID` and `CONTRIB`, which could be manipulated to alter the behavior of the skill in unexpected ways.File System Access
File System Access via local-llm-review
SKILL.md
The skill creates and modifies files in the `~/.gstack/sessions` directory, which could be used to store or exfiltrate sensitive data if the skill is compromised.Badge
Add the Anomity scan badge for document-release to your README.
How Anomity governs this at runtime
Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.
Book a 30-minute demo to see your own skill inventory.
Methodology and disputes
Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of document-release? Report an issue or request a rescan.




