windows-disk-cleanup
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes various PowerShell commands and scripts to perform system maintenance. These include file deletions via
Remove-Item, process management withStop-Process(specifically for Docker Desktop), and calls to external CLI tools such asnpm,uv, anddocker. These actions are central to the skill's utility and are protected by a mandatory two-phase process (Discover, then Execute) that requires user confirmation. - [INDIRECT_PROMPT_INJECTION]: The skill contains an attack surface for indirect prompt injection because it processes untrusted data from the user's file system and external analysis tools.
- Ingestion points: The skill ingests data from WizTree screenshots (analyzed by the agent) and file system metadata (scanned by
cleanup.ps1,clean_venvs.ps1, anddownloads_report.ps1). - Boundary markers: The skill enforces a mandatory read-only "Discover" phase to report findings and requires "explicit user approval" before moving to the "Execute" phase.
- Capability inventory: The skill possesses the capability to delete files across various system and user directories, stop running processes, and clear application caches.
- Sanitization: No explicit sanitization or filtering is performed on the file names or directory structures read during the scanning process.
Audit Metadata