smart-commit

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill uses standard development commands (git, npm) for managing source code changes and running local tests. These actions are restricted to the local environment and the project scope.
  • [DATA_EXPOSURE]: The skill includes a proactive security measure to scan staged changes for hardcoded secrets, API keys, and debug statements before committing, which is a defensive best practice.
  • [COMMAND_EXECUTION]: The use of git and npm is consistent with the skill's stated purpose of being a 'smart commit' tool. It does not perform unauthorized network operations or download external scripts.
  • [INDIRECT_PROMPT_INJECTION]: While the skill reads git diff output (external data), it is used solely for code quality review and commit message generation within a restricted developer workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:50 PM
Security Audit — agent-trust-hub — smart-commit