commit-work

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a secure git commit workflow that emphasizes manual review and granular staging.
  • [SAFE]: It incorporates explicit security sanity checks, instructing the agent to verify the absence of secrets, API tokens, or accidental debug logs before finalizing a commit.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted repository data through git diff and executes local verification commands like tests or build scripts.
  • Ingestion points: SKILL.md (Reviewing code changes via git diff and git diff --cached).
  • Boundary markers: Not explicitly defined for the diff content.
  • Capability inventory: Execution of git commands and local repository verification scripts (tests/lint/build).
  • Sanitization: None.
  • Note: This surface is inherent to the skill's primary function and is mitigated by the structured review process.
  • [COMMAND_EXECUTION]: Utilizes standard git tooling and local scripts for code management. No malicious or unauthorized command patterns were identified.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:54 AM