using-git-worktrees

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the repository which could be manipulated to influence agent behavior.
  • Ingestion points: The skill reads directory preferences from CLAUDE.md and detects project types by checking for the presence of package.json, requirements.txt, Cargo.toml, and go.mod in the current workspace.
  • Boundary markers: No explicit boundary markers or instructions to ignore embedded commands are present when processing the contents of CLAUDE.md or project configuration files.
  • Capability inventory: The skill has the capability to execute shell commands for git management (git worktree add), dependency installation (npm install, pip install, cargo build, go mod download), and automated testing (npm test, pytest, cargo test) as described in the 'Creation Steps' and 'Verify Clean Baseline' sections of SKILL.md.
  • Sanitization: There is no evidence of sanitization or strict schema validation for the data retrieved from CLAUDE.md before it is interpolated into shell command paths or logic flow.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 09:19 PM
Security Audit — agent-trust-hub — using-git-worktrees