commit-changes

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill reads pull request templates from the repository (.github/pull_request_template.md) to guide the commit message generation. This represents an ingestion point for external data; however, the skill uses this data to map context rather than executing it, which is standard behavior for its primary purpose.\n- [COMMAND_EXECUTION]: The skill executes standard git commands (status, diff, add, commit) for version control. It uses a shell HEREDOC pattern for the commit command to securely handle multi-line input and avoid command injection.\n- [EXTERNAL_DOWNLOADS]: The skill uses npx commitlint for message validation. This involves fetching the commitlint package from the official npm registry if it is not already available in the execution environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 11:12 AM
Security Audit — agent-trust-hub — commit-changes