commit-work
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a secure git commit workflow that emphasizes manual review and granular staging.
- [SAFE]: It incorporates explicit security sanity checks, instructing the agent to verify the absence of secrets, API tokens, or accidental debug logs before finalizing a commit.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted repository data through
git diffand executes local verification commands like tests or build scripts. - Ingestion points:
SKILL.md(Reviewing code changes viagit diffandgit diff --cached). - Boundary markers: Not explicitly defined for the diff content.
- Capability inventory: Execution of
gitcommands and local repository verification scripts (tests/lint/build). - Sanitization: None.
- Note: This surface is inherent to the skill's primary function and is mitigated by the structured review process.
- [COMMAND_EXECUTION]: Utilizes standard
gittooling and local scripts for code management. No malicious or unauthorized command patterns were identified.
Audit Metadata