atomic-commits

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill is subject to indirect prompt injection because it consumes untrusted data from the git repository environment (diffs, status, untracked files). It lacks explicit boundary delimiters and sanitization for natural language instructions that might be embedded in the processed code. Ingestion points: Git status and diff outputs specified in SKILL.md. Boundary markers: Absent. Capability inventory: Repository modification via git add and git commit. Sanitization: Redaction of secrets is required, but there is no mechanism for escaping or ignoring instructions in the data.
  • [COMMAND_EXECUTION]: The skill uses shell tools to execute git commands. It implements strong preventative measures by explicitly banning broad staging commands and requiring user confirmation for specific file or hunk staging, minimizing the risk of accidental or malicious bulk file operations.
  • [DATA_EXFILTRATION]: The skill includes logic to scan diffs for secret-like content and mandates redaction before committing, which is a proactive security measure against accidental credential exposure.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 04:19 AM
Security Audit — agent-trust-hub — atomic-commits