smart-commit
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill uses standard development commands (
git,npm) for managing source code changes and running local tests. These actions are restricted to the local environment and the project scope. - [DATA_EXPOSURE]: The skill includes a proactive security measure to scan staged changes for hardcoded secrets, API keys, and debug statements before committing, which is a defensive best practice.
- [COMMAND_EXECUTION]: The use of
gitandnpmis consistent with the skill's stated purpose of being a 'smart commit' tool. It does not perform unauthorized network operations or download external scripts. - [INDIRECT_PROMPT_INJECTION]: While the skill reads
git diffoutput (external data), it is used solely for code quality review and commit message generation within a restricted developer workflow.
Audit Metadata