git-guardrails

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill automates several git operations and uses specialized tools to manage the repository.
  • The scripts/git-commit.sh bash script validates and runs git commit to finalize changes, using robust validation against control characters and invalid formats.
  • Step 7 in SKILL.md invokes skill-changelog with parameters to update the CHANGELOG.md file, which involves writing to the local file system.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8) by ingesting untrusted commit subjects from the repository history.
  • Ingestion points: Commit messages are ingested from the git repository during the version decision process (Step 6) and changelog generation.
  • Boundary markers: The skill does not define specific boundary markers or instruct the agent to ignore instructions found within commit messages, creating a surface where malicious commit text could be interpreted as instructions.
  • Capability inventory: The agent can write to project files (CHANGELOG.md) and execute git commands such as push and commit.
  • Sanitization: While the git-commit.sh script validates outgoing messages effectively, historical commits retrieved from the repository are not sanitized or validated before being evaluated by the agent's decision logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 07:15 PM
Security Audit — agent-trust-hub — git-guardrails