gitmoji
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a legitimate text-processing tool without any detected malicious patterns or hidden logic.
- [COMMAND_EXECUTION]: The instructions clearly restrict the agent from executing shell commands or git operations, stating it only generates copyable text.
- [EXTERNAL_DOWNLOADS]: References are made to the official gitmoji.dev website and its GitHub repository for documentation purposes; these are well-known resources and do not involve remote code execution.
- [DATA_EXFILTRATION]: The skill does not access credentials, sensitive configuration files, or local user data.
- [PROMPT_INJECTION]: The skill ingests git diffs provided by the user, which constitutes an untrusted input surface; however, the lack of exploitable capabilities (like command execution or network access) renders this risk negligible.
Audit Metadata