skills/ulpi-io/skills/commit/Gen Agent Trust Hub

commit

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements strong security guardrails for git operations, including mandatory scanning for hardcoded secrets, .env files, and git conflict markers before any staging occurs.
  • [SAFE]: Autonomous execution is prevented by the disable-model-invocation: true flag, ensuring the skill only runs upon explicit user request, which mitigates the risk of unauthorized repository modifications.
  • [INDIRECT_PROMPT_INJECTION]: The skill has the surface area for indirect prompt injection because it reads untrusted data (git diffs and file contents) and has access to the Bash tool. This risk is effectively managed by the skill's design, which requires explicit user invocation and staging of files by name. 1. Ingestion points: SKILL.md (Step 1 and Step 2) reads git diffs and specific file contents. 2. Boundary markers: The skill requires explicit staging by name and user confirmation for ambiguous changes. 3. Capability inventory: The skill uses Bash, Read, Glob, and Grep tools. 4. Sanitization: The skill relies on user review of the drafted commit and explicit tool invocation rather than automated sanitization of diff content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 12:23 PM