draft-commit-message

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references and fetches commit message guidelines from the author's repository on GitHub (github.com/mtngtools/agents).
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted code changes to draft commit messages, creating a surface where embedded instructions could influence the output.
  • Ingestion points: Code changes and git logs as described in SKILL.md.
  • Boundary markers: Absent; no delimiters are used to wrap the input data.
  • Capability inventory: Limited to drafting and outputting text.
  • Sanitization: Absent; no filtering or escaping of input data is performed.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 01:31 PM
Security Audit — agent-trust-hub — draft-commit-message