commit
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill mandates the execution of
git add -Ato stage all project changes andgit committo finalize them. The use of the-Aflag is broad and will stage every change in the working directory. - [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: The skill ingests data from local project files and git diffs to automatically generate Conventional Commit messages (SKILL.md).
- Boundary markers: There are no explicit delimiters or boundary markers defined to isolate the processed codebase content from the skill's instructions.
- Capability inventory: The agent has the capability to execute shell commands, specifically
git addandgit commit(SKILL.md). - Sanitization: The skill does not implement sanitization or validation of the ingested code content before using it to generate the commit message output.
Audit Metadata