worktrees

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes multiple git commands, such as git worktree, git switch, and git status, to manage repository state and ensure feature development occurs in isolated workspaces.
  • [COMMAND_EXECUTION]: The skill utilizes a vendor-provided CLI tool, @ericrisco/rsc, through npx to automate the cleanup of safe-to-remove worktrees.
  • [EXTERNAL_DOWNLOADS]: The skill uses npx to fetch and execute the @ericrisco/rsc package from the npm registry. This is a standard operation within the skill's specific development context and the package belongs to the identified author.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests configuration data from 02-DOCS/wiki/harness/user-profile.md to determine the 'accompaniment dial' level (L0-L3), which influences agent narration and verbosity. This metadata represents an ingestion point for potentially untrusted data that could influence the agent's behavior.
  • Ingestion points: 02-DOCS/wiki/harness/user-profile.md (read from the local file system).
  • Boundary markers: None specified for the content of the profile file.
  • Capability inventory: File system and git repository manipulation, plus the ability to execute the npx package runner.
  • Sanitization: None; the skill maps the numeric value from the dial directly to instructions for agent verbosity.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 11:12 PM
Security Audit — agent-trust-hub — worktrees