skills/hk-hub/agentskills/git-commit/Gen Agent Trust Hub

git-commit

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to execute standard git commands such as git diff, git add, and git commit. These operations are limited to the repository scope and follow common development workflows.
  • [INDIRECT_PROMPT_INJECTION]: The agent analyzes data from git diff which could contain untrusted content from the codebase. Ingestion points: Output from git diff and git diff --staged. Boundary markers: The instructions do not define specific delimiters for separating diff content. Capability inventory: Includes the ability to stage and commit files to the repository. Sanitization: There is no explicit sanitization of the diff output before processing.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill provides a safety warning against committing sensitive files such as .env, credentials.json, or private keys. This instruction mitigates the risk of accidental secret exposure.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — git-commit