manage-remotes

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a proactive security layer via scripts/inspect_remotes.py, which parses and sanitizes Git remote URLs to remove embedded credentials (usernames and passwords). This prevents sensitive authentication data from being included in the agent's context or displayed to the user.
  • [COMMAND_EXECUTION]: The Python script uses subprocess.run to call the git binary. The implementation is secure as it passes arguments as a list rather than a shell string, effectively mitigating shell injection risks and ensuring the command execution is confined to intended parameters.
  • [DATA_EXFILTRATION]: The instructions in SKILL.md explicitly enforce the use of the sanitization helper and prohibit the printing of raw or unclassified remote strings. This establishes a clear boundary and fail-safe mechanism to prevent the accidental disclosure of sensitive repository topology.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 03:46 AM
Security Audit — agent-trust-hub — manage-remotes