dev-git-commit-message
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
git diff --stagedto inspect changes in the repository to generate commit message suggestions. This is a core part of its documented functionality. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from staged files and user-supplied commit messages. However, it uses deterministic regex-based validation in
scripts/commit_validator.pyand does not evaluate or execute the content of the messages. The capability inventory is limited to local git operations and static validation. - [EXTERNAL_DOWNLOADS]: The documentation files (
references/changelog-generation-guide.md,references/commit-message-antipatterns.md) provide instructions for installing common industry tools such asnpm install commitlintornpx husky init. These downloads are not executed by the skill itself but are provided as developer guidance for repository setup. - [SAFE]: The Python script
scripts/commit_validator.pyis written using only the standard library (argparse, json, os, re, sys, collections, datetime, typing) and contains no dangerous dynamic execution patterns likeeval()orexec().
Audit Metadata