using-git-worktrees
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the repository which could be manipulated to influence agent behavior.
- Ingestion points: The skill reads directory preferences from
CLAUDE.mdand detects project types by checking for the presence ofpackage.json,requirements.txt,Cargo.toml, andgo.modin the current workspace. - Boundary markers: No explicit boundary markers or instructions to ignore embedded commands are present when processing the contents of
CLAUDE.mdor project configuration files. - Capability inventory: The skill has the capability to execute shell commands for git management (
git worktree add), dependency installation (npm install,pip install,cargo build,go mod download), and automated testing (npm test,pytest,cargo test) as described in the 'Creation Steps' and 'Verify Clean Baseline' sections ofSKILL.md. - Sanitization: There is no evidence of sanitization or strict schema validation for the data retrieved from
CLAUDE.mdbefore it is interpolated into shell command paths or logic flow.
Audit Metadata