commit-changes
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill reads pull request templates from the repository (
.github/pull_request_template.md) to guide the commit message generation. This represents an ingestion point for external data; however, the skill uses this data to map context rather than executing it, which is standard behavior for its primary purpose.\n- [COMMAND_EXECUTION]: The skill executes standardgitcommands (status,diff,add,commit) for version control. It uses a shell HEREDOC pattern for the commit command to securely handle multi-line input and avoid command injection.\n- [EXTERNAL_DOWNLOADS]: The skill usesnpx commitlintfor message validation. This involves fetching thecommitlintpackage from the official npm registry if it is not already available in the execution environment.
Audit Metadata