finishing-a-development-branch

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data from external environment outputs which could be manipulated to influence agent behavior.
  • Ingestion points: The skill reads output from project-specific test suites (npm test, cargo test, pytest, go test) in Step 1 and evaluates branch names and merge-base outputs in Step 2.
  • Boundary markers: Absent; there are no explicit delimiters or instructions telling the agent to ignore potentially malicious text embedded within the test failures or Git metadata.
  • Capability inventory: The skill possesses capabilities to execute shell commands (git, npm, gh), perform file system modifications (git branch -d, git worktree remove), and conduct network operations (git push, gh pr create).
  • Sanitization: No filtering or sanitization of the external output is performed before it is presented to the agent context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 09:19 PM
Security Audit — agent-trust-hub — finishing-a-development-branch