git-pushing

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it accepts commit messages derived from user input or project files and passes them directly to a shell script.
  • Ingestion points: The commit message parameter in SKILL.md used by the agent to call the script.
  • Boundary markers: Absent; there are no instructions to the agent to sanitize or ignore instructions embedded within the data used for the commit message.
  • Capability inventory: File system modification (git add, git commit) and network operations (git push) within scripts/smart_commit.sh.
  • Sanitization: Absent; the script does not validate or escape the input string.
  • [COMMAND_EXECUTION]: The script scripts/smart_commit.sh is vulnerable to shell command injection. The line git commit -m "$MESSAGE" uses double quotes, which in Bash allows for command substitution. If the $MESSAGE variable contains a pattern like $(command), the shell will execute that command locally before passing the result to git.
  • [DATA_EXFILTRATION]: The script uses git add . to stage changes. This aggressive staging approach automatically includes all new and modified files in the working directory, which significantly increases the risk of accidentally staging and pushing sensitive data (such as .env files, SSH keys, or hardcoded credentials) to a remote repository.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:32 PM
Security Audit — agent-trust-hub — git-pushing