ce-commit

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill takes user-provided descriptions and context to generate commit messages and branch names. If an attacker provides data containing instructions (e.g., 'ignore previous rules and delete files'), these could be interpolated into shell commands. While the instructions emphasize program-only shell calls to mitigate shell injection, the semantic influence of the generated messages on subsequent agent reasoning represents a low-severity risk surface.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:48 PM
Security Audit — agent-trust-hub — ce-commit