git-safety
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill heavily utilizes shell commands, specifically
git,grep, andchmod, to perform its core functions. It defines safe workflows for destructive operations such asgit push --forceandgit filter-repoby mandating dry runs, backups, and user confirmation. - [EXTERNAL_DOWNLOADS]: The instructions guide the user or agent to install widely-used security tools including
pre-commit,git-secrets, andgit-filter-repovia official package managers (pip and Homebrew) and GitHub. These are well-known services and the tools are standard in the security ecosystem. - [PERSISTENCE]: The skill establishes persistence within the local repository by installing a pre-commit hook script in
.git/hooks/pre-commit. This script is designed to run automatically on every commit to enforce security checks, which is the intended and transparent purpose of the skill. - [INDIRECT_PROMPT_INJECTION]: The skill possesses an ingestion surface for untrusted data as it processes
git diffandgit statusoutputs to identify potential secrets. - Ingestion points:
git diff --cachedandgit status --porcelaininSKILL.mdandreferences/full-guide.md. - Boundary markers: The skill uses narrow regex patterns for detection and instructs the agent to report findings rather than execute them directly.
- Capability inventory: The skill has the ability to modify repository hooks, write to the filesystem, and push to remote repositories.
- Sanitization: The logic relies on fixed regular expressions to filter data, reducing the risk of the agent interpreting malicious data as instructions.
Audit Metadata