skills/observeinc/cli/commit/Gen Agent Trust Hub

commit

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a standard utility for automating git commit message generation. It does not contain any executable code, remote dependencies, or instructions to access sensitive files.
  • [DATA_EXPOSURE]: There are no hardcoded credentials or exfiltration patterns. The mention of 'CURSOR_API_KEY' in the examples is a placeholder used to demonstrate error handling for missing environment variables, which is a standard development practice.
  • [PROMPT_INJECTION]: The instructions are focused on formatting and organizing commit messages. There are no attempts to override system safety guidelines or ignore prior instructions.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes git diffs (external data). While this is a theoretical attack surface, the instructions do not implement unsafe interpolation or lack boundaries that would increase risk beyond the baseline for this type of tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 11:04 PM
Security Audit — agent-trust-hub — commit