conventional-commits

Pass

Audited by Gen Agent Trust Hub on Feb 19, 2026

Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
  • [NO_CODE] (SAFE): The skill consists entirely of Markdown files (SKILL.md, assets/examples.md, references/types.md) and does not include any executable Python, Node.js, or shell scripts.
  • [Indirect Prompt Injection] (LOW): The skill is designed to process external data which could contain malicious instructions. 1. Ingestion points: The skill analyzes 'staged changes' as described in the Workflow section of SKILL.md. 2. Boundary markers: No delimiters or instructions to ignore embedded commands are present. 3. Capability inventory: No tools, network access, or system execution capabilities are defined in the skill files. 4. Sanitization: No input validation or sanitization logic is specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 19, 2026, 07:03 AM