Git Commit Message Generator

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward Git commit-message helper that reads staged diffs to suggest a conventional commit message, with no executable code or hidden install behavior found.

Before using it, review what you have staged and avoid invoking it on secrets, credentials, regulated data, or proprietary code you are not comfortable having the agent analyze. Treat the generated commit message as a draft and review it before committing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill repeatedly states it will read staged diffs, file paths, and branch-name context to generate a commit message, but it does not clearly and prominently disclose that this repository content may be transmitted to the AI for analysis. That can expose proprietary code, secrets accidentally staged in diffs, internal issue IDs, or sensitive branch metadata without the user's informed consent.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal