cleanup
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes Git commands (
git status,git ls-files,git rm,git log) and performs file system operations including deletion (os.remove), recursive directory removal (shutil.rmtree), and file archival (shutil.move) as part of its core cleanup functionality. These actions are triggered via the CLI and include confirmation prompts unless overridden by the --force flag. - [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface because it reads and processes the content of all files in the project directory to identify references and documentation markers without sanitization.
- Ingestion points:
cleanup.pyreads project file contents through theread_file_contentfunction. - Boundary markers: Absent. Results are summarized into a text-based cleanup plan or log.
- Capability inventory: The skill has the capability to delete files, remove directories, and move artifacts to a specified storage path.
- Sanitization: No content sanitization or instruction-ignoring delimiters are used when processing the files.
Audit Metadata