skills/bobosun0713/skills/git-commit/Gen Agent Trust Hub

git-commit

Warn

Audited by Gen Agent Trust Hub on Mar 25, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes multiple shell commands to manage a git repository, specifically git status, git add ., git diff --staged, and git commit -m "<message>". These commands change the state of the local environment and are performed without user review.
  • [PROMPT_INJECTION]: The instructions contain multiple directives aimed at suppressing user confirmation and review, such as "Always generate a commit immediately — never ask," "Execute ... directly," and "never ask the user to confirm any of these." This pattern overrides standard safety guidelines that require human approval for state-changing or shell-based operations.
  • [DATA_EXFILTRATION]: The automated execution of git add . without user review presents a risk of staging and committing sensitive files (like .env, .pem keys, or credentials) that may exist in the working directory but are not excluded by a .gitignore file, effectively exposing them in the git history.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection. 1. Ingestion points: untrusted data enters via git diff --staged and the {content} argument in SKILL.md. 2. Boundary markers: Absent; there are no delimiters or warnings to ignore embedded instructions. 3. Capability inventory: The skill can execute git add and git commit via shell. 4. Sanitization: Absent; external content is interpolated directly into the commit message process without escaping or validation.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 25, 2026, 02:54 PM
Security Audit — agent-trust-hub — git-commit