git-pushing

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes local file names and diff content to generate commit messages and status reports, creating a surface for indirect instructions.
  • Ingestion points: scripts/smart_commit.sh ingests data from the local file system using git diff --cached --name-only and git diff --cached --stat.
  • Boundary markers: Absent. Output from git commands is echoed back to the agent without isolation.
  • Capability inventory: The skill can stage all files, create commits, and push to remote servers.
  • Sanitization: None. File names and diff statistics are used directly in the script's logic and output.
  • [DATA_EXFILTRATION]: The skill performs network operations to transmit local data to a remote git server.
  • Evidence: The script scripts/smart_commit.sh executes git push to synchronize local changes with a remote repository.
  • Risk: By using git add ., the skill stages all changes in the workspace. This can result in sensitive files (e.g., credentials, .env files) being committed and uploaded to the remote server if they are not properly ignored.
  • [COMMAND_EXECUTION]: The skill relies on executing various git and shell commands within a bash script environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 01:57 PM
Security Audit — agent-trust-hub — git-pushing