skills/vainjs/skills/commit/Gen Agent Trust Hub

commit

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill mandates the execution of git add -A to stage all project changes and git commit to finalize them. The use of the -A flag is broad and will stage every change in the working directory.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: The skill ingests data from local project files and git diffs to automatically generate Conventional Commit messages (SKILL.md).
  • Boundary markers: There are no explicit delimiters or boundary markers defined to isolate the processed codebase content from the skill's instructions.
  • Capability inventory: The agent has the capability to execute shell commands, specifically git add and git commit (SKILL.md).
  • Sanitization: The skill does not implement sanitization or validation of the ingested code content before using it to generate the commit message output.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 07:12 AM
Security Audit — agent-trust-hub — commit