git-pushing
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues detected. The skill performs expected git operations.
- [COMMAND_EXECUTION]: The skill executes a local shell script
scripts/smart_commit.shthat runs standard git commands (git add,git commit,git push). These operations are consistent with the skill's stated purpose. - [DATA_EXFILTRATION]: The skill performs a
git pushto the repository's configuredorigin. This is a standard operation for sharing code and does not involve sending data to unauthorized or unknown external domains. - [PROMPT_INJECTION]: The skill processes untrusted data for commit messages and file staging. (1) Ingestion points: The commit message is taken from user input and files are staged via
git add .. (2) Boundary markers: No delimiters are used to separate user data from the command context. (3) Capability inventory: The skill can read local files and write to a remote repository via git. (4) Sanitization: The commit message is quoted in the shell script to prevent command injection.
Audit Metadata