commit-summary
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the local repository (git diffs, logs, and status) which could contain malicious instructions designed to influence the agent's summary or commit behavior.
- Ingestion points: The skill reads external data via
git status,git log, andgit diffas defined in the 'Workflow' section ofSKILL.mdand the 'Workflow' section ofreferences/what-did-i-get-done-procedure.md. - Boundary markers: There are no explicit delimiters or specific 'ignore instructions' warnings used when the agent interpolates the content of git diffs or logs into its context.
- Capability inventory: The skill possesses the ability to execute file and repository modifications via
git addandgit commitas defined in the 'Workflow' section ofSKILL.md. - Sanitization: The skill includes a specific security workflow (Step 3 in
SKILL.md) that instructs the agent to guard against staging secrets,.envfiles, or credentials, and to delegate to agit-safetytool if sensitive content is detected.
Audit Metadata