dev-commit

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to read and interpret repository states, file contents, and git diffs. This represents an attack surface where maliciously crafted data within a repository could attempt to influence the agent's actions.
  • Ingestion points: git status, git diff, and repository file contents (SKILL.md).
  • Boundary markers: The skill uses a defined "Commit Contract" and "Guardrails" to structure behavior, but does not specify delimiters for external content.
  • Capability inventory: Execution of shell commands including git, npm, and repository-specific test/build scripts (SKILL.md).
  • Sanitization: No explicit sanitization of file content or diff output is mentioned before processing.
  • [COMMAND_EXECUTION]: The instructions require the agent to run various shell commands for validation and environment preparation.
  • Evidence: The skill specifies running npm ci, npm run build, and "repo's targeted tests, lint, typecheck, build, or documented verification commands" (SKILL.md). These commands are executed based on the presence of project configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 02:02 AM
Security Audit — agent-trust-hub — dev-commit