clean-branches
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from local and remote git environments that could be influenced by untrusted sources.
- Ingestion points: Local branch names are fetched via
git branch(SKILL.md, Step 1) and pull request metadata is fetched from GitHub viagh pr list(SKILL.md, Step 2). - Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat branch names or PR titles as data and to ignore any instructions potentially embedded within them.
- Capability inventory: The skill performs potentially destructive operations including branch deletion (
git branch -D) and branch checkouts/merges (git checkout,git merge). - Sanitization: No sanitization or validation of the ingested strings is performed before they are processed by the agent or displayed in the summary table.
Audit Metadata