undo-and-recover
Pass
Audited by Gen Agent Trust Hub on Jul 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is designed for local Git operations and includes strong defensive instructions to prevent security risks associated with untrusted repository data:
- Command Safety: It mandates the use of option termination (
--) and literal pathspec handling to ensure that file or branch names containing dashes or special characters are not misinterpreted as CLI flags (mitigating command injection). - Input Validation: It requires using
git check-ref-formatfor new references and full OIDs to ensure integrity and prevent collision or ambiguity. - User Control: Confirmation is explicitly required before any destructive action (e.g., discarding changes, deleting untracked files, or moving refs).
- [SAFE]: No signs of data exfiltration, credential harvesting, remote code execution, or obfuscation were found. The skill does not attempt to access network resources or sensitive environment variables.
- [SAFE]: (Indirect Prompt Injection Surface): The skill inherently processes data from Git repositories (such as commit messages or diffs) which could be attacker-controlled. However, the skill explicitly defines safety rules for handling this data:
- Ingestion points: Git index, working-tree changes, reflogs, and commit objects (specified in
SKILL.mdandreferences/recovery-matrix.md). - Boundary markers: While explicit prompt delimiters are not defined for textual data, the skill instructs the agent to treat all metadata and targets as untrusted.
- Capability inventory: Actionable capabilities are restricted to local Git recovery and commit creation.
- Sanitization: Employs literal pathspec handling and reference validation to sanitize inputs before CLI execution.
Audit Metadata