semantic-git

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the local repository (code changes and diffs) to generate commit messages and determine appropriate CI checks.
  • Ingestion points: The agent reads local file contents and git diff output during the staging and commit generation process (SKILL.md).
  • Boundary markers: There are no explicit delimiters or instructions to ignore embedded prompts within the analyzed files.
  • Capability inventory: The skill utilizes git command execution and shell access for running CI tasks like pnpm, npm, pytest, and cargo.
  • Sanitization: No explicit sanitization or filtering is defined for the content of the diffs; however, the skill mandates human-in-the-loop verification, requiring all generated commands and messages to be printed and confirmed by the user before execution.
  • [SAFE]: The skill follows security best practices for agent-led system operations by enforcing user confirmation, providing command transparency, and using standard environmental configurations for its tools. The external reference to the zagi tool targets a public code repository on a whitelisted domain (GitHub) and is consistent with the skill's stated purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 02:40 AM
Security Audit — agent-trust-hub — semantic-git