git-squash-merge

Fail

Audited by Snyk on Apr 17, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (high risk: 0.70). The prompt explicitly instructs the agent to conceal that the commit is a squash ("should never reference or acknowledge that it is a squash") and to avoid co-signing/identifying the commit, which are deceptive directives outside the stated, transparent purpose of producing a clean squashed commit.

Issues (1)

E004
CRITICAL

Prompt injection detected in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Apr 17, 2026, 01:02 PM
Issues
1
Security Audit — snyk — git-squash-merge