commit
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes standard Git commands (
git diff --cachedandgit commit) to perform its stated function of generating and applying commit messages. - [DATA_EXPOSURE_AND_EXFILTRATION]: The skill reads staged file changes to generate context for the commit message. This operation is localized to the user's repository and is necessary for the skill's primary purpose.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data (staged code changes) which could potentially contain malicious instructions. However, the skill implements a human-in-the-loop confirmation step before any permanent action (committing), which effectively mitigates the risk of the agent executing unintended instructions derived from the code diff.
Audit Metadata