undo-and-recover

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed for local Git operations and includes strong defensive instructions to prevent security risks associated with untrusted repository data:
  • Command Safety: It mandates the use of option termination (--) and literal pathspec handling to ensure that file or branch names containing dashes or special characters are not misinterpreted as CLI flags (mitigating command injection).
  • Input Validation: It requires using git check-ref-format for new references and full OIDs to ensure integrity and prevent collision or ambiguity.
  • User Control: Confirmation is explicitly required before any destructive action (e.g., discarding changes, deleting untracked files, or moving refs).
  • [SAFE]: No signs of data exfiltration, credential harvesting, remote code execution, or obfuscation were found. The skill does not attempt to access network resources or sensitive environment variables.
  • [SAFE]: (Indirect Prompt Injection Surface): The skill inherently processes data from Git repositories (such as commit messages or diffs) which could be attacker-controlled. However, the skill explicitly defines safety rules for handling this data:
  • Ingestion points: Git index, working-tree changes, reflogs, and commit objects (specified in SKILL.md and references/recovery-matrix.md).
  • Boundary markers: While explicit prompt delimiters are not defined for textual data, the skill instructs the agent to treat all metadata and targets as untrusted.
  • Capability inventory: Actionable capabilities are restricted to local Git recovery and commit creation.
  • Sanitization: Employs literal pathspec handling and reference validation to sanitize inputs before CLI execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 04:50 PM
Security Audit — agent-trust-hub — undo-and-recover