worktrees
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill facilitates the execution of various Git commands, including
git worktree,git merge, andgit reset. The risk is mitigated by explicit requirements for the agent to seek user confirmation before running any destructive or state-changing commands.\n- [INDIRECT_PROMPT_INJECTION]: The skill uses variable placeholders like<slug>and<branch-name>which are interpolated into shell commands.\n - Ingestion points: Variables derived from user tasks or manual input are used to construct Git commands in
SKILL.md.\n - Boundary markers: The protocol mandates a 'Pre-Flight Checklist' and 'Mandatory User Confirmation' to ensure the user reviews the exact operation before execution.\n
- Capability inventory: The skill uses
gitvia the shell to manage worktrees, branches, and commits.\n - Sanitization: The skill relies on human-in-the-loop validation via mandatory confirmation prompts rather than programmatic escaping.
Audit Metadata