manage-remotes
Pass
Audited by Gen Agent Trust Hub on Jul 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a proactive security layer via
scripts/inspect_remotes.py, which parses and sanitizes Git remote URLs to remove embedded credentials (usernames and passwords). This prevents sensitive authentication data from being included in the agent's context or displayed to the user. - [COMMAND_EXECUTION]: The Python script uses
subprocess.runto call thegitbinary. The implementation is secure as it passes arguments as a list rather than a shell string, effectively mitigating shell injection risks and ensuring the command execution is confined to intended parameters. - [DATA_EXFILTRATION]: The instructions in
SKILL.mdexplicitly enforce the use of the sanitization helper and prohibit the printing of raw or unclassified remote strings. This establishes a clear boundary and fail-safe mechanism to prevent the accidental disclosure of sensitive repository topology.
Audit Metadata