git-commit
Warn
Audited by Gen Agent Trust Hub on Mar 25, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes multiple shell commands to manage a git repository, specifically
git status,git add .,git diff --staged, andgit commit -m "<message>". These commands change the state of the local environment and are performed without user review. - [PROMPT_INJECTION]: The instructions contain multiple directives aimed at suppressing user confirmation and review, such as "Always generate a commit immediately — never ask," "Execute ... directly," and "never ask the user to confirm any of these." This pattern overrides standard safety guidelines that require human approval for state-changing or shell-based operations.
- [DATA_EXFILTRATION]: The automated execution of
git add .without user review presents a risk of staging and committing sensitive files (like.env,.pemkeys, or credentials) that may exist in the working directory but are not excluded by a.gitignorefile, effectively exposing them in the git history. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection. 1. Ingestion points: untrusted data enters via
git diff --stagedand the{content}argument in SKILL.md. 2. Boundary markers: Absent; there are no delimiters or warnings to ignore embedded instructions. 3. Capability inventory: The skill can executegit addandgit commitvia shell. 4. Sanitization: Absent; external content is interpolated directly into the commit message process without escaping or validation.
Audit Metadata