commit

Warn

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The instructions explicitly direct the agent to suppress its identity by forbidding the use of "Co-Authored-By" headers or "Generated with Claude" messages. This is an attempt to override standard transparency and attribution protocols by forcing the agent to appear as a human user.\n- [COMMAND_EXECUTION]: The skill performs shell command execution by invoking a local script located at $CLAUDE_PROJECT_DIR/.claude/scripts/generate-reasoning.sh. This relies on a project-specific script whose contents are not controlled by the skill itself.\n- [DYNAMIC_EXECUTION]: The skill passes dynamic arguments (the commit hash and message) to a bash script. This pattern can lead to command injection if the commit message contains malicious shell metacharacters and the script does not safely handle or escape its inputs.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from git diff and git status output to formulate commit plans and messages, exposing a surface for malicious code to influence agent behavior.\n
  • Ingestion points: The agent reads session history, git status, and git diff output from the current working directory (SKILL.md, step 1).\n
  • Boundary markers: No specific delimiters or "ignore instructions" markers are used to separate the content of the diff from the agent's decision-making logic.\n
  • Capability inventory: The skill possesses the capability to execute shell commands (git, bash) and modify the repository state via commits.\n
  • Sanitization: The skill lacks any description of escaping or validation for the commit messages generated from the diff data before they are passed to the reasoning script.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 18, 2026, 05:11 PM
Security Audit — agent-trust-hub — commit