clean-branches

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from local and remote git environments that could be influenced by untrusted sources.
  • Ingestion points: Local branch names are fetched via git branch (SKILL.md, Step 1) and pull request metadata is fetched from GitHub via gh pr list (SKILL.md, Step 2).
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat branch names or PR titles as data and to ignore any instructions potentially embedded within them.
  • Capability inventory: The skill performs potentially destructive operations including branch deletion (git branch -D) and branch checkouts/merges (git checkout, git merge).
  • Sanitization: No sanitization or validation of the ingested strings is performed before they are processed by the agent or displayed in the summary table.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 03:57 PM
Security Audit — agent-trust-hub — clean-branches