windows-disk-cleanup

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes various PowerShell commands and scripts to perform system maintenance. These include file deletions via Remove-Item, process management with Stop-Process (specifically for Docker Desktop), and calls to external CLI tools such as npm, uv, and docker. These actions are central to the skill's utility and are protected by a mandatory two-phase process (Discover, then Execute) that requires user confirmation.
  • [INDIRECT_PROMPT_INJECTION]: The skill contains an attack surface for indirect prompt injection because it processes untrusted data from the user's file system and external analysis tools.
  • Ingestion points: The skill ingests data from WizTree screenshots (analyzed by the agent) and file system metadata (scanned by cleanup.ps1, clean_venvs.ps1, and downloads_report.ps1).
  • Boundary markers: The skill enforces a mandatory read-only "Discover" phase to report findings and requires "explicit user approval" before moving to the "Execute" phase.
  • Capability inventory: The skill possesses the capability to delete files across various system and user directories, stop running processes, and clear application caches.
  • Sanitization: No explicit sanitization or filtering is performed on the file names or directory structures read during the scanning process.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 04:32 AM