commit
Pass
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted Git diff data to generate commit messages. This creates a surface for indirect prompt injection where malicious instructions embedded in the code changes could influence the agent's behavior during message composition.\n
- Ingestion points: Git diff output from ai-commit prepare (SKILL.md Step 3).\n
- Boundary markers: The instructions do not define delimiters or specific ignore directives for the diff content.\n
- Capability inventory: The agent can create commits via ai-commit and resolve findings in ai-coord.\n
- Sanitization: No sanitization or validation of the diff content is performed.\n- [COMMAND_EXECUTION]: The skill executes several CLI tools including git, ai-commit, ai-coord, and uv. It also executes an internal Python script (scripts/git-squash.py) to manage branch squashing. The script uses safe subprocess call patterns (list-based arguments without shell=True), protecting against command injection.
Audit Metadata