commit-message
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/analyze_changes.pyexecutes localgitcommands (git status,git diff) using thesubprocess.runfunction. The commands are passed as lists of arguments, which is a secure practice that prevents shell injection vulnerabilities. This behavior is consistent with the skill's stated purpose of analyzing git repositories. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data in the form of file paths and change statuses retrieved from the local filesystem via git commands. While a repository could contain maliciously named files intended to trick the agent, the risk is minimal as the script's logic is primarily focused on classification and formatting. * Ingestion points: The
get_changesmethod inscripts/analyze_changes.pyingests output fromgit statusandgit diff. * Boundary markers: No delimiters or explicit warnings are used to separate ingested data from instructions. * Capability inventory: The skill's primary capability is executing localgitcommands. * Sanitization: No sanitization of file paths is performed before analysis.
Audit Metadata