conventional-commits

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains a strict directive to conceal AI involvement in the commit process, stating the output "MUST be indistinguishable from one written by a human developer" and forbidding attribution trailers. This instruction promotes deceptive behavior regarding the origin of the code changes.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the codebase through git diff commands.\n
  • Ingestion points: Reads the output of git diff --cached and git diff as described in the workflow in SKILL.md.\n
  • Boundary markers: No specific delimiters or instructions are provided to the agent to ignore potential commands or instructions embedded within the code diffs.\n
  • Capability inventory: The skill uses native Write tools for file creation and Bash for command execution (git commit).\n
  • Sanitization: The skill employs a security best practice by writing the message to a file and using the -F flag with git commit, which prevents shell interpretation of the message content and mitigates command injection risks.\n- [COMMAND_EXECUTION]: The skill performs git operations. It correctly identifies the safety risks of inline commit messages and provides a secure alternative by using file-based commit messages and avoiding shell redirects or heredocs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 03:45 PM
Security Audit — agent-trust-hub — conventional-commits