commit-push

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill facilitates the execution of shell commands for Git operations, including context gathering (git status, git diff), staging changes (git add -A), committing with generated messages, and pushing to remote repositories.
  • [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to analyze untrusted data from git diff and git log to draft commit messages, creating an attack surface where malicious instructions hidden in code comments or commit history could attempt to influence agent behavior.
  • Ingestion points: The outputs of git diff, git diff --cached, and git log are ingested into the agent context in SKILL.md (Step 1).
  • Boundary markers: The skill does not provide explicit delimiters or warnings to the agent to ignore instructions embedded within the code changes being analyzed.
  • Capability inventory: The skill uses shell execution capabilities to interact with the file system and network via the git CLI.
  • Sanitization: There is no evidence of sanitization or filtering applied to the Git output before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 09:16 AM
Security Audit — agent-trust-hub — commit-push