commit-changes

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns detected. The skill outlines standard Git workflows with a high emphasis on safety and verification.
  • [COMMAND_EXECUTION]: The skill uses Git commands (git add, git commit) but provides explicit safety guidelines to prevent command injection. It mandates using separate arguments, literal pathspecs (--literal-pathspecs, :(literal)), and the -- delimiter to ensure user-provided filenames are treated as data rather than options.
  • [DATA_EXFILTRATION]: No network exfiltration or unauthorized data access patterns were found. The skill explicitly warns against exposing secrets in commit messages.
  • [PROMPT_INJECTION]: The instructions do not contain attempts to override system prompts or safety filters. Instead, they define strict operational boundaries for the agent.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies a potential attack surface by ingesting untrusted data (filenames, commit messages) but mitigates this via strict command-line argument handling and mandatory verification steps.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 04:49 PM
Security Audit — agent-trust-hub — commit-changes