git-commit

Warn

Audited by Gen Agent Trust Hub on Jul 4, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use "required escalation" (typically sudo) if git commit fails with permission errors like Operation not permitted. Encouraging the use of elevated privileges for repository operations introduces a risk of privilege escalation.
  • [COMMAND_EXECUTION]: The execution rules suggest dynamic command construction: "For a single path, reuse the same command shape and append -- <path>." If a repository contains maliciously crafted filenames with shell metacharacters (e.g., ; rm -rf /), it could lead to arbitrary command execution when the agent runs the diff command.
  • [PROMPT_INJECTION]: The skill is susceptible to Indirect Prompt Injection (Category 8). It analyzes the "staged raw patch" as the "only source of truth" to generate commit messages without using boundary markers or sanitizing the content. Malicious instructions embedded in the code changes could influence the agent's behavior or the generated output.
  • Ingestion points: Reads output from git diff --staged (staged raw patch) in the context collection phase.
  • Boundary markers: Absent. The skill does not instruct the agent to ignore or delimit instructions found within the diff data.
  • Capability inventory: Executes shell commands (git status, git diff, git add, git commit, rm).
  • Sanitization: Absent. The diff content is processed directly to draft commit messages.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 4, 2026, 04:36 PM
Security Audit — agent-trust-hub — git-commit