skills/tisfeng/skills/git-commit/Gen Agent Trust Hub

git-commit

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes local Git commands and Python scripts (validate-commit-message.py and commit-change-stats.py) to handle repository operations and validation. The subprocess calls in the Python scripts are implemented using argument lists with shell=False, which prevents shell injection. Git commands like rev-parse use the --end-of-options flag to protect against argument injection from user-provided revision strings.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data in the form of Git staged diffs and file contents when drafting commit messages. Ingestion points: Git repository state (HEAD, branch, status, staged/unstaged diffs, untracked content) accessed in SKILL.md. Boundary markers: The skill requires the agent to present a full preview in a text code block for user approval before committing. It also follows a strict Commit Message Contract with specific bilingual headers and paragraph structures. Capability inventory: Local filesystem writes (message files), and local Git operations (git add, git commit, git rev-parse, git diff). The skill explicitly prohibits git push, rebase, and merge. Sanitization: The validate-commit-message.py script performs structural validation, enforcing character limits and specific keyword labels, while explicitly disallowing Markdown code fences inside the commit message to prevent rendering issues or further injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 04:17 PM
Security Audit — agent-trust-hub — git-commit