semantic-git
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the local repository (code changes and diffs) to generate commit messages and determine appropriate CI checks.
- Ingestion points: The agent reads local file contents and
git diffoutput during the staging and commit generation process (SKILL.md). - Boundary markers: There are no explicit delimiters or instructions to ignore embedded prompts within the analyzed files.
- Capability inventory: The skill utilizes
gitcommand execution and shell access for running CI tasks likepnpm,npm,pytest, andcargo. - Sanitization: No explicit sanitization or filtering is defined for the content of the diffs; however, the skill mandates human-in-the-loop verification, requiring all generated commands and messages to be printed and confirmed by the user before execution.
- [SAFE]: The skill follows security best practices for agent-led system operations by enforcing user confirmation, providing command transparency, and using standard environmental configurations for its tools. The external reference to the
zagitool targets a public code repository on a whitelisted domain (GitHub) and is consistent with the skill's stated purpose.
Audit Metadata