using-git-worktrees

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes various shell commands to detect current Git workspace state and manage worktrees, including git rev-parse and git worktree add.
  • [EXTERNAL_DOWNLOADS]: The skill triggers dependency installation using standard package managers (npm, pip, poetry, go, cargo) to download code from well-known official registries based on the project manifest.
  • [REMOTE_CODE_EXECUTION]: The skill automatically runs build commands (cargo build) and test suites (npm test, pytest, go test) defined within the repository. This represents a risk of executing malicious code if the repository configuration contains harmful scripts.
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect injection via untrusted project data. 1. Ingestion points: Project manifest files such as package.json, Cargo.toml, and requirements.txt. 2. Boundary markers: None; the skill automatically executes commands based on file presence. 3. Capability inventory: Execution of arbitrary shell scripts via build and test tools. 4. Sanitization: No validation or filtering is performed on the scripts defined in the project configuration before execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 03:58 PM
Security Audit — agent-trust-hub — using-git-worktrees