git-commit
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes local Git commands and Python scripts (validate-commit-message.py and commit-change-stats.py) to handle repository operations and validation. The subprocess calls in the Python scripts are implemented using argument lists with shell=False, which prevents shell injection. Git commands like rev-parse use the --end-of-options flag to protect against argument injection from user-provided revision strings.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data in the form of Git staged diffs and file contents when drafting commit messages. Ingestion points: Git repository state (HEAD, branch, status, staged/unstaged diffs, untracked content) accessed in SKILL.md. Boundary markers: The skill requires the agent to present a full preview in a text code block for user approval before committing. It also follows a strict Commit Message Contract with specific bilingual headers and paragraph structures. Capability inventory: Local filesystem writes (message files), and local Git operations (git add, git commit, git rev-parse, git diff). The skill explicitly prohibits git push, rebase, and merge. Sanitization: The validate-commit-message.py script performs structural validation, enforcing character limits and specific keyword labels, while explicitly disallowing Markdown code fences inside the commit message to prevent rendering issues or further injection.
Audit Metadata