finishing-a-development-branch

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes standard development tools and Git commands to manage project workflows.
  • Commands include project-specific test runners (npm test, cargo test, pytest, go test) and Git operations for merging, pushing, and worktree management.
  • These executions are central to the skill's primary purpose and follow standard development practices.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a potential attack surface common to development tools that ingest external output.
  • Ingestion points: Test suite outputs and Git branch names are read into the agent's context in SKILL.md (Step 1 and Step 5).
  • Boundary markers: The skill uses shell heredocs (EOF) as a delimiter when constructing Pull Request bodies in Step 4.
  • Capability inventory: The skill has the ability to execute shell commands, perform Git merges/deletions, and interact with the GitHub API via the gh CLI.
  • Sanitization: There is no explicit sanitization of test failure logs or branch names, though the risk is mitigated by the structured selection of options rather than autonomous execution of data-derived commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:18 AM
Security Audit — agent-trust-hub — finishing-a-development-branch