commit
Warn
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The instructions explicitly direct the agent to suppress its identity by forbidding the use of "Co-Authored-By" headers or "Generated with Claude" messages. This is an attempt to override standard transparency and attribution protocols by forcing the agent to appear as a human user.\n- [COMMAND_EXECUTION]: The skill performs shell command execution by invoking a local script located at
$CLAUDE_PROJECT_DIR/.claude/scripts/generate-reasoning.sh. This relies on a project-specific script whose contents are not controlled by the skill itself.\n- [DYNAMIC_EXECUTION]: The skill passes dynamic arguments (the commit hash and message) to a bash script. This pattern can lead to command injection if the commit message contains malicious shell metacharacters and the script does not safely handle or escape its inputs.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data fromgit diffandgit statusoutput to formulate commit plans and messages, exposing a surface for malicious code to influence agent behavior.\n - Ingestion points: The agent reads session history,
git status, andgit diffoutput from the current working directory (SKILL.md, step 1).\n - Boundary markers: No specific delimiters or "ignore instructions" markers are used to separate the content of the diff from the agent's decision-making logic.\n
- Capability inventory: The skill possesses the capability to execute shell commands (
git,bash) and modify the repository state via commits.\n - Sanitization: The skill lacks any description of escaping or validation for the commit messages generated from the diff data before they are passed to the reasoning script.
Audit Metadata