skills/kortix-ai/suna/commit-dis/Gen Agent Trust Hub

commit-dis

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized data access were detected. The skill is purely instructional and follows local development best practices.\n- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it ingests untrusted data (filenames) from the local environment via git status. However, the risk is mitigated by explicit instructions to confirm files and avoid automated processing. Ingestion points: Output of git status --short; Boundary markers: None; Capability inventory: git add, git commit; Sanitization: None.\n- [COMMAND_EXECUTION]: The skill utilizes standard git commands (git add, git commit, git status) to manage the repository. These are appropriate for the skill's stated purpose and do not involve administrative privileges or dangerous execution patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 11:48 AM
Security Audit — agent-trust-hub — commit-dis