dev-worktree
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands to manage Git worktrees (e.g.,
git worktree add,git branch --show-current) and to perform dependency installation and project builds using various ecosystem-specific tools (e.g.,npm,pnpm,uv,poetry,cargo,gradlew). These operations are consistent with the skill's stated purpose of setting up a development workspace. - [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it bases its execution logic on untrusted data from the filesystem.
- Ingestion points: The skill reads project lockfiles, manifests (like
package.jsonorrequirements.txt), and tooling configurations (e.g.,agents/openai.yaml,SKILL.md) to detect the development ecosystem. - Boundary markers: There are no explicit instructions to the agent to disregard instructions that might be embedded in the repository metadata it reads.
- Capability inventory: The skill possesses capabilities to write to the filesystem (modifying
.gitignore), execute arbitrary repository-native bootstrap commands, and build the project. - Sanitization: The skill does not implement specific sanitization for the project manifests it processes, relying on standard package manager behavior for the detected ecosystem.
Audit Metadata