git-guardrails
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill automates several git operations and uses specialized tools to manage the repository.
- The
scripts/git-commit.shbash script validates and runsgit committo finalize changes, using robust validation against control characters and invalid formats. - Step 7 in
SKILL.mdinvokesskill-changelogwith parameters to update theCHANGELOG.mdfile, which involves writing to the local file system. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8) by ingesting untrusted commit subjects from the repository history.
- Ingestion points: Commit messages are ingested from the git repository during the version decision process (Step 6) and changelog generation.
- Boundary markers: The skill does not define specific boundary markers or instruct the agent to ignore instructions found within commit messages, creating a surface where malicious commit text could be interpreted as instructions.
- Capability inventory: The agent can write to project files (
CHANGELOG.md) and execute git commands such aspushandcommit. - Sanitization: While the
git-commit.shscript validates outgoing messages effectively, historical commits retrieved from the repository are not sanitized or validated before being evaluated by the agent's decision logic.
Audit Metadata