git-commit
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
Bashtool to execute standardgitcommands such asgit diff,git add, andgit commit. These operations are limited to the repository scope and follow common development workflows. - [INDIRECT_PROMPT_INJECTION]: The agent analyzes data from
git diffwhich could contain untrusted content from the codebase. Ingestion points: Output fromgit diffandgit diff --staged. Boundary markers: The instructions do not define specific delimiters for separating diff content. Capability inventory: Includes the ability to stage and commit files to the repository. Sanitization: There is no explicit sanitization of the diff output before processing. - [DATA_EXPOSURE_AND_EXFILTRATION]: The skill provides a safety warning against committing sensitive files such as
.env,credentials.json, or private keys. This instruction mitigates the risk of accidental secret exposure.
Audit Metadata