conventional-commits

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed with a strict 'message-only' scope. It explicitly prohibits commands that would modify the repository index or history, such as git commit or git add.
  • [DATA_EXPOSURE]: The skill accesses local repository data via git diff and git log. A safety mechanism is in place to identify and redact secret-like information (e.g., API keys) from the output if they are detected in the diff evidence.
  • [INDIRECT_PROMPT_INJECTION]: As the skill processes content from git diffs, it is susceptible to indirect prompt injection where an attacker could place malicious instructions in a commit. However, the skill's limited output capability (text generation only) and lack of tool execution permissions significantly mitigate this risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 04:19 AM
Security Audit — agent-trust-hub — conventional-commits