finishing-a-development-branch
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data from external environment outputs which could be manipulated to influence agent behavior.
- Ingestion points: The skill reads output from project-specific test suites (
npm test,cargo test,pytest,go test) in Step 1 and evaluates branch names and merge-base outputs in Step 2. - Boundary markers: Absent; there are no explicit delimiters or instructions telling the agent to ignore potentially malicious text embedded within the test failures or Git metadata.
- Capability inventory: The skill possesses capabilities to execute shell commands (
git,npm,gh), perform file system modifications (git branch -d,git worktree remove), and conduct network operations (git push,gh pr create). - Sanitization: No filtering or sanitization of the external output is performed before it is presented to the agent context.
Audit Metadata