git-commit

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from workspace changes to organize atomic commits and generate messages, creating a surface for indirect instructions.
  • Ingestion points: Workspace changes (uncommitted code and files) described in SKILL.md.
  • Boundary markers: None specified to delimit user content from instructions.
  • Capability inventory: The delegated agent (commit-craft) performs workspace reads and git commit operations.
  • Sanitization: No evidence of sanitization or filtering of workspace content before context interpolation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 04:53 PM
Security Audit — agent-trust-hub — git-commit