cleanup

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes Git commands (git status, git ls-files, git rm, git log) and performs file system operations including deletion (os.remove), recursive directory removal (shutil.rmtree), and file archival (shutil.move) as part of its core cleanup functionality. These actions are triggered via the CLI and include confirmation prompts unless overridden by the --force flag.
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface because it reads and processes the content of all files in the project directory to identify references and documentation markers without sanitization.
  • Ingestion points: cleanup.py reads project file contents through the read_file_content function.
  • Boundary markers: Absent. Results are summarized into a text-based cleanup plan or log.
  • Capability inventory: The skill has the capability to delete files, remove directories, and move artifacts to a specified storage path.
  • Sanitization: No content sanitization or instruction-ignoring delimiters are used when processing the files.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:34 AM
Security Audit — agent-trust-hub — cleanup