commit-changes
Pass
Audited by Gen Agent Trust Hub on Jul 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns detected. The skill outlines standard Git workflows with a high emphasis on safety and verification.
- [COMMAND_EXECUTION]: The skill uses Git commands (
git add,git commit) but provides explicit safety guidelines to prevent command injection. It mandates using separate arguments, literal pathspecs (--literal-pathspecs,:(literal)), and the--delimiter to ensure user-provided filenames are treated as data rather than options. - [DATA_EXFILTRATION]: No network exfiltration or unauthorized data access patterns were found. The skill explicitly warns against exposing secrets in commit messages.
- [PROMPT_INJECTION]: The instructions do not contain attempts to override system prompts or safety filters. Instead, they define strict operational boundaries for the agent.
- [INDIRECT_PROMPT_INJECTION]: The skill identifies a potential attack surface by ingesting untrusted data (filenames, commit messages) but mitigates this via strict command-line argument handling and mandatory verification steps.
Audit Metadata