git-worktree-setup

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill involves reading and executing setup commands and baseline checks from the repository being worked on. This functionality presents an indirect prompt injection surface as malicious repository content could attempt to influence the agent's actions during the setup phase.
  • Ingestion points: Repository instructions and tool configuration files (e.g., package manifests) as described in SKILL.md.
  • Boundary markers: There are no explicit instructions for using delimiters to isolate data from the repository from the agent's execution context.
  • Capability inventory: The skill permits the execution of subprocesses for project setup, dependency management, and baseline check commands (SKILL.md).
  • Sanitization: The instructions include a manual step for the agent to inspect state and lockfiles, but do not provide automated sanitization for the commands derived from the repository.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 05:37 AM
Security Audit — agent-trust-hub — git-worktree-setup