git-toolkit

Pass

Audited by Gen Agent Trust Hub on May 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides a robust framework for git/GitHub operations, relying on standard system tools and clear user interactions.\n- [SAFE]: It enforces a human-in-the-loop security model, where all commands that modify the repository or GitHub state are presented for user review and manual execution.\n- [SAFE]: The skill includes a dedicated secret-pattern scanning capability used to audit commit messages and PR descriptions for accidental credential leakage before they are displayed or authored.\n- [SAFE]: It correctly distinguishes between local and remote-authoritative data sources, particularly when handling forks and cross-repository pull requests, to ensure accuracy and prevent accidental overwrites.\n- [SAFE]: While the skill processes untrusted input such as PR bodies and commit messages, it mitigates indirect prompt injection risks by treating this content as data to be analyzed rather than instructions to be followed, and by surfacing all results for user verification.
Audit Metadata
Risk Level
SAFE
Analyzed
May 20, 2026, 10:51 PM
Security Audit — agent-trust-hub — git-toolkit