dev-worktree

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands to manage Git worktrees (e.g., git worktree add, git branch --show-current) and to perform dependency installation and project builds using various ecosystem-specific tools (e.g., npm, pnpm, uv, poetry, cargo, gradlew). These operations are consistent with the skill's stated purpose of setting up a development workspace.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it bases its execution logic on untrusted data from the filesystem.
  • Ingestion points: The skill reads project lockfiles, manifests (like package.json or requirements.txt), and tooling configurations (e.g., agents/openai.yaml, SKILL.md) to detect the development ecosystem.
  • Boundary markers: There are no explicit instructions to the agent to disregard instructions that might be embedded in the repository metadata it reads.
  • Capability inventory: The skill possesses capabilities to write to the filesystem (modifying .gitignore), execute arbitrary repository-native bootstrap commands, and build the project.
  • Sanitization: The skill does not implement specific sanitization for the project manifests it processes, relying on standard package manager behavior for the detected ecosystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 02:02 AM
Security Audit — agent-trust-hub — dev-worktree