commit-changes
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes standard Git CLI tools (git add, git commit, git log, git diff) to perform its primary functions. These operations are scoped to the local repository and are appropriate for the skill's purpose.
- [COMMAND_EXECUTION]: The skill executes an included shell script (advance-pipeline-lock.sh) to manage internal state via a lock file. Technical review of the script confirms it uses jq for safe JSON manipulation and standard atomic file moves (mv) to update project-specific metadata.
- [PROMPT_INJECTION]: The skill processes potentially untrusted data by reading previous commit messages (git log) to determine repository-specific formatting styles. While this represents an indirect ingestion surface, the data is used for style matching rather than command generation, posing no significant risk.
- [EXTERNAL_DOWNLOADS]: The skill does not perform any network operations or download external content. All scripts and references are bundled locally within the skill's directory.
Audit Metadata