dev-git-commit-message

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses git diff --staged to inspect changes in the repository to generate commit message suggestions. This is a core part of its documented functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from staged files and user-supplied commit messages. However, it uses deterministic regex-based validation in scripts/commit_validator.py and does not evaluate or execute the content of the messages. The capability inventory is limited to local git operations and static validation.
  • [EXTERNAL_DOWNLOADS]: The documentation files (references/changelog-generation-guide.md, references/commit-message-antipatterns.md) provide instructions for installing common industry tools such as npm install commitlint or npx husky init. These downloads are not executed by the skill itself but are provided as developer guidance for repository setup.
  • [SAFE]: The Python script scripts/commit_validator.py is written using only the standard library (argparse, json, os, re, sys, collections, datetime, typing) and contains no dangerous dynamic execution patterns like eval() or exec().
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — dev-git-commit-message