commit-summary

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the local repository (git diffs, logs, and status) which could contain malicious instructions designed to influence the agent's summary or commit behavior.
  • Ingestion points: The skill reads external data via git status, git log, and git diff as defined in the 'Workflow' section of SKILL.md and the 'Workflow' section of references/what-did-i-get-done-procedure.md.
  • Boundary markers: There are no explicit delimiters or specific 'ignore instructions' warnings used when the agent interpolates the content of git diffs or logs into its context.
  • Capability inventory: The skill possesses the ability to execute file and repository modifications via git add and git commit as defined in the 'Workflow' section of SKILL.md.
  • Sanitization: The skill includes a specific security workflow (Step 3 in SKILL.md) that instructs the agent to guard against staging secrets, .env files, or credentials, and to delegate to a git-safety tool if sensitive content is detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 05:10 AM
Security Audit — agent-trust-hub — commit-summary