using-git-worktrees
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes various shell commands to detect current Git workspace state and manage worktrees, including
git rev-parseandgit worktree add. - [EXTERNAL_DOWNLOADS]: The skill triggers dependency installation using standard package managers (npm, pip, poetry, go, cargo) to download code from well-known official registries based on the project manifest.
- [REMOTE_CODE_EXECUTION]: The skill automatically runs build commands (
cargo build) and test suites (npm test,pytest,go test) defined within the repository. This represents a risk of executing malicious code if the repository configuration contains harmful scripts. - [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect injection via untrusted project data. 1. Ingestion points: Project manifest files such as
package.json,Cargo.toml, andrequirements.txt. 2. Boundary markers: None; the skill automatically executes commands based on file presence. 3. Capability inventory: Execution of arbitrary shell scripts via build and test tools. 4. Sanitization: No validation or filtering is performed on the scripts defined in the project configuration before execution.
Audit Metadata