conventional-commits
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains a strict directive to conceal AI involvement in the commit process, stating the output "MUST be indistinguishable from one written by a human developer" and forbidding attribution trailers. This instruction promotes deceptive behavior regarding the origin of the code changes.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the codebase through git diff commands.\n
- Ingestion points: Reads the output of
git diff --cachedandgit diffas described in the workflow in SKILL.md.\n - Boundary markers: No specific delimiters or instructions are provided to the agent to ignore potential commands or instructions embedded within the code diffs.\n
- Capability inventory: The skill uses native
Writetools for file creation andBashfor command execution (git commit).\n - Sanitization: The skill employs a security best practice by writing the message to a file and using the
-Fflag withgit commit, which prevents shell interpretation of the message content and mitigates command injection risks.\n- [COMMAND_EXECUTION]: The skill performs git operations. It correctly identifies the safety risks of inline commit messages and provides a secure alternative by using file-based commit messages and avoiding shell redirects or heredocs.
Audit Metadata