git-pushing
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it accepts commit messages derived from user input or project files and passes them directly to a shell script.
- Ingestion points: The commit message parameter in
SKILL.mdused by the agent to call the script. - Boundary markers: Absent; there are no instructions to the agent to sanitize or ignore instructions embedded within the data used for the commit message.
- Capability inventory: File system modification (
git add,git commit) and network operations (git push) withinscripts/smart_commit.sh. - Sanitization: Absent; the script does not validate or escape the input string.
- [COMMAND_EXECUTION]: The script
scripts/smart_commit.shis vulnerable to shell command injection. The linegit commit -m "$MESSAGE"uses double quotes, which in Bash allows for command substitution. If the$MESSAGEvariable contains a pattern like$(command), the shell will execute that command locally before passing the result to git. - [DATA_EXFILTRATION]: The script uses
git add .to stage changes. This aggressive staging approach automatically includes all new and modified files in the working directory, which significantly increases the risk of accidentally staging and pushing sensitive data (such as.envfiles, SSH keys, or hardcoded credentials) to a remote repository.
Audit Metadata