git-commit-messages
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes output from
git diff --staged, which is untrusted data. Malicious code or comments within a commit could attempt to influence the AI's behavior during message generation. \n - Ingestion points: The staged diff content accessed via
git diff --staged(SKILL.md). \n - Boundary markers: Absent. The instructions do not mandate the use of delimiters or 'ignore' instructions for the diff data. \n
- Capability inventory: Execution of Git shell commands including
git status,git diff, andgit add(SKILL.md). \n - Sanitization: Absent. Diff content is used directly for analysis without validation or sanitization. \n- [COMMAND_EXECUTION]: The skill involves executing Git commands in the shell (
git status,git diff,git add). While typical for repository management, this enables interaction with the local file system and repository metadata.
Audit Metadata