commit-staged
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses shell commands to interact with the repository, specifically
git diff --cached --name-onlyandgit diff --cached, and performs commits using HEREDOC syntax. These operations are within the scope of its primary purpose. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon data that may be controlled by an external attacker, creating a vulnerability surface.
- Ingestion points: The skill reads staged diffs via
git diffand incorporates "extra invocation text" and "session history findings" (motivation/rationale) into its logic. - Boundary markers: The instructions do not specify any delimiters or safety markers to differentiate between instructions and the data being processed from the diffs or history.
- Capability inventory: The skill has the ability to read files, modify the
README.mdfile, and executegit commitcommands. - Sanitization: There is no evidence of sanitization, validation, or escaping of the ingested data before it is interpolated into commit messages or used to determine documentation updates.
Audit Metadata