git-guardrails-claude-code

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a defensive mechanism to prevent accidental execution of destructive Git commands by the agent. This is achieved through a local bash script used as a PreToolUse hook.
  • [COMMAND_EXECUTION]: The instructions include standard commands to make the local safety script executable (chmod +x) and to update the agent's configuration files (settings.json). These operations are necessary for the skill's primary purpose of establishing guardrails.
  • [EXTERNAL_DOWNLOADS]: The documentation references a source repository on GitHub for transparency and attribution, but the skill does not perform any remote code downloads or execution at runtime.
  • [INDIRECT_PROMPT_INJECTION]: The safety script processes input from the agent's tool execution pipeline (tool_input) to identify blocked commands. This interaction is restricted to string pattern matching for filtering purposes and does not introduce executable vulnerabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 01:39 AM
Security Audit — agent-trust-hub — git-guardrails-claude-code