tidy-up

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a maintenance utility with robust safety controls and no detected malicious patterns.\n- [COMMAND_EXECUTION]: The skill uses standard git and filesystem commands (git worktree, git branch, du) to manage local clutter. These are appropriate for its stated purpose.\n- [INDIRECT_PROMPT_INJECTION]: The skill reads local filesystem metadata which could theoretically contain malicious instructions, but the mandatory user review process effectively mitigates this surface risk.\n
  • Ingestion points: Directory listings and git status outputs (found in references/targets.md).\n
  • Boundary markers: Explicit inventory and approval steps (found in SKILL.md).\n
  • Capability inventory: File deletion and git branch/worktree management.\n
  • Sanitization: Human-in-the-loop approval of all cleanup actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 11:26 PM
Security Audit — agent-trust-hub — tidy-up