git-pushing

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues detected. The skill performs expected git operations.
  • [COMMAND_EXECUTION]: The skill executes a local shell script scripts/smart_commit.sh that runs standard git commands (git add, git commit, git push). These operations are consistent with the skill's stated purpose.
  • [DATA_EXFILTRATION]: The skill performs a git push to the repository's configured origin. This is a standard operation for sharing code and does not involve sending data to unauthorized or unknown external domains.
  • [PROMPT_INJECTION]: The skill processes untrusted data for commit messages and file staging. (1) Ingestion points: The commit message is taken from user input and files are staged via git add .. (2) Boundary markers: No delimiters are used to separate user data from the command context. (3) Capability inventory: The skill can read local files and write to a remote repository via git. (4) Sanitization: The commit message is quoted in the shell script to prevent command injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 06:19 PM
Security Audit — agent-trust-hub — git-pushing