agent-commit-message-crafter

Pass

Audited by Gen Agent Trust Hub on Mar 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of markdown instructions designed to guide an AI agent in crafting semantic commit messages. No malicious logic or obfuscated code was detected within the instructions or metadata.\n- [PROMPT_INJECTION]: The skill analyzes code diffs which are external, untrusted inputs. This creates a surface for indirect prompt injection; however, the skill's focus on structured output and semantic rules, combined with a lack of dangerous tool invocations based on that input, mitigates this risk. No direct prompt injection or safety bypass instructions were found.\n- [COMMAND_EXECUTION]: The imported agent specification mentions Bash, Grep, and Glob as available tools. These are used locally for repository analysis (reading files and diffs). The skill itself does not provide any shell scripts or execute arbitrary commands.\n- [EXTERNAL_DOWNLOADS]: The skill footer references the official Anthropic Claude Code website, which is a trusted domain. No unauthorized remote code downloads or external network requests are performed by the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 5, 2026, 01:13 AM