conventional-commits
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is designed with a strict 'message-only' scope. It explicitly prohibits commands that would modify the repository index or history, such as
git commitorgit add. - [DATA_EXPOSURE]: The skill accesses local repository data via
git diffandgit log. A safety mechanism is in place to identify and redact secret-like information (e.g., API keys) from the output if they are detected in the diff evidence. - [INDIRECT_PROMPT_INJECTION]: As the skill processes content from git diffs, it is susceptible to indirect prompt injection where an attacker could place malicious instructions in a commit. However, the skill's limited output capability (text generation only) and lack of tool execution permissions significantly mitigate this risk.
Audit Metadata