skills/asiaostrich/code-buddy/commit/Gen Agent Trust Hub

commit

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is configured to use git through the Bash tool (e.g., git status, git diff, git commit) to perform its core functions. This is documented in the allowed-tools section of SKILL.md.
  • [PROMPT_INJECTION]: A potential indirect prompt injection vulnerability exists where malicious content in staged files could influence the AI's generated commit message. Ingestion points: staged file content via git diff in SKILL.md. Boundary markers: no specific isolation instructions or delimiters are provided in the guide. Capability inventory: tool permissions include git commit in the YAML frontmatter. Sanitization: no filtering of git output is performed before AI analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 03:37 AM
Security Audit — agent-trust-hub — commit