git-commit
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the repository via git diff commands to generate commit messages. This creates a surface for indirect prompt injection if malicious instructions are embedded in the code being committed. However, the impact is limited by the skill's constrained workflow and safety protocols. 1. Ingestion points: git diff, git diff --staged, and git status in SKILL.md. 2. Boundary markers: No delimiters are used to separate diff content from instructions. 3. Capability inventory: git add and git commit operations. 4. Sanitization: Relies on the provided Git Safety Protocol and agent logic.
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill features a Git Safety Protocol that specifically instructs the agent to never commit secrets such as .env files, credentials.json, or private keys, reducing the risk of accidental data exposure.
- [SAFE]: The skill uses standard git functionality for its stated purpose without any detected obfuscation, remote code execution, privilege escalation, or persistence mechanisms.
Audit Metadata