commit-history-review
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is restricted to read-only operations on repository metadata, such as commit logs and diff summaries. It explicitly prohibits destructive actions, history rewriting (rebase, amend, reset), and remote operations (push).
- [DATA_EXFILTRATION]: No network-capable commands (e.g., curl, wget) or external URL references were found. The skill instructions specifically mandate that the agent must not expose secrets or sensitive values.
- [COMMAND_EXECUTION]: The operating contract strictly limits tool usage to inspection commands. It provides clear boundaries preventing the execution of any commands that modify the local or remote state of the repository.
- [PROMPT_INJECTION]: The instructions do not contain patterns for bypassing safety filters or overriding system behavior. Instead, they reinforce safe operating boundaries and evidence-based reporting.
- [INDIRECT_PROMPT_INJECTION]: While the skill processes commit messages (untrusted data), it possesses no 'write' or 'execute' capabilities that could be exploited via malicious commit content. The risk is minimized by the read-only nature of the toolset.
Audit Metadata