commit
Pass
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a standard utility for automating git commit message generation. It does not contain any executable code, remote dependencies, or instructions to access sensitive files.
- [DATA_EXPOSURE]: There are no hardcoded credentials or exfiltration patterns. The mention of 'CURSOR_API_KEY' in the examples is a placeholder used to demonstrate error handling for missing environment variables, which is a standard development practice.
- [PROMPT_INJECTION]: The instructions are focused on formatting and organizing commit messages. There are no attempts to override system safety guidelines or ignore prior instructions.
- [INDIRECT_PROMPT_INJECTION]: The skill processes git diffs (external data). While this is a theoretical attack surface, the instructions do not implement unsafe interpolation or lack boundaries that would increase risk beyond the baseline for this type of tool.
Audit Metadata