edit-commit-history

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions demonstrate high security awareness by explicitly warning against indirect prompt injection from repository-controlled text (commit messages, patches, logs). It directs the agent to treat such content strictly as data and ignore any embedded instructions that might attempt to expand scope or bypass safety protocols.
  • [SAFE]: Command execution safety is prioritized. The skill advises avoiding shell interpolation, using boundary markers (--), and accounting for the potential execution of repository-provided hooks or filters by isolating them with minimal privileges.
  • [SAFE]: The workflow for remote updates is designed for safety, requiring exact object ID leases (--force-with-lease=<ref>:<oid>) rather than destructive force pushes, which prevents accidental overwriting of concurrent remote work.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 03:46 AM
Security Audit — agent-trust-hub — edit-commit-history