clonedeps
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches source code from external Git repositories provided at runtime by the librarian agent. While these sources are determined dynamically, the skill implements multiple safeguards. Evidence: SKILL.md Step 4 describes cloning sources into .slim/clonedeps/repos/. Mitigation: The skill requires HTTPS URLs, mandates user confirmation before cloning, and explicitly forbids running any installation or build scripts from the cloned repositories.
- [COMMAND_EXECUTION]: The skill uses shell-based Git commands to manage the external repositories. Evidence: SKILL.md Step 3 and 4 outline the use of git ls-remote and git clone.
- [INDIRECT_PROMPT_INJECTION]: By bringing external source code into the local environment for inspection, the skill creates a surface where malicious instructions embedded in that code could influence the agent's future actions. Ingestion points: Files within the .slim/clonedeps/repos/ directory in SKILL.md. Boundary markers: The skill designates these clones as read-only and uses ignore files to manage visibility, though it lacks explicit instructions for the agent to ignore prompt-like content inside the library source. Capability inventory: The skill has permissions to execute Git commands and modify project configuration files like .gitignore and AGENTS.md. Sanitization: Repository names are sanitized to prevent path traversal issues during folder creation, and URLs with embedded credentials are rejected.
Audit Metadata