unfuck-my-git-state
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes repository metadata, such as branch names and worktree paths, which may originate from untrusted sources.
- Ingestion points:
scripts/snapshot_git_state.shcaptures output from commands likegit status,git branch, andgit worktree.scripts/guided_repair_plan.shthen reads these files to generate recovery advice. - Boundary markers: The scripts do not use explicit delimiters or "ignore embedded instructions" headers when presenting captured data to the agent.
- Capability inventory: The skill provides templates for powerful Git commands (
git symbolic-ref,git worktree prune) and manual file system operations (removing.git/worktreesdirectories). - Sanitization: The scripts perform basic filtering (removing comments and whitespace) but do not explicitly sanitize or escape external content before inclusion in the repair plan.
Audit Metadata