skills/tisfeng/easydict/git-commit/Gen Agent Trust Hub

git-commit

Fail

Audited by Gen Agent Trust Hub on Mar 22, 2026

Risk Level: HIGHCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to automatically seek privilege escalation if the git commit command fails with permission errors (e.g., Operation not permitted) or encounters lock file issues in the .git directory. Directing an agent to escalate privileges in response to system errors is a high-risk pattern.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it ingests and analyzes untrusted data from the local repository without proper sanitization or boundary markers.
  • Ingestion points: git diff --staged and git log --oneline -10 in SKILL.md.
  • Boundary markers: Absent. The skill does not define delimiters or provide instructions to ignore embedded commands within the diff output.
  • Capability inventory: File write (commit_message.txt), shell command execution (git commit), and file deletion (rm) in SKILL.md.
  • Sanitization: Absent. There is no evidence of filtering or escaping logic applied to external repository content before the agent processes it for commit message generation.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 22, 2026, 08:29 PM
Security Audit — agent-trust-hub — git-commit