using-git-worktrees

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes shell commands to facilitate development workflows. This includes project setup via npm install, cargo build, pip install -r requirements.txt, poetry install, and go mod download, as well as running tests using npm test, cargo test, pytest, and go test within the newly created worktree.\n- [REMOTE_CODE_EXECUTION]: The skill automatically performs package installation and build steps which involve fetching and executing external dependencies defined in the project's configuration files (package.json, Cargo.toml, etc.). These are standard development operations but represent the execution of external code.\n- [INDIRECT_PROMPT_INJECTION]: The skill contains a vulnerability surface where it automatically triggers command execution based on configuration files found within the repository it is operating on.\n
  • Ingestion points: Project configuration files (package.json, Cargo.toml, requirements.txt, pyproject.toml, go.mod) referenced in the creation steps.\n
  • Boundary markers: None identified; commands are executed based on the presence of the files.\n
  • Capability inventory: Full shell command execution via project-specific package managers and test runners.\n
  • Sanitization: No sanitization or integrity verification of the configuration files is performed before executing the associated build and install commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:49 PM
Security Audit — agent-trust-hub — using-git-worktrees