worktree
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides a workflow for reviewing external pull requests that facilitates the ingestion and execution of untrusted code.
- Ingestion points: External code fetched from pull request branches (e.g.,
git fetch origin pull/123/head) as documented in SKILL.md. - Boundary markers: None. The skill does not include delimiters or warnings to treat external PR content as untrusted.
- Capability inventory: The skill instructions recommend running
npm installandnpm testwithin the checked-out PR worktree, which can execute arbitrary code via package scripts. - Sanitization: None. There are no steps to validate or sanitize the external code before execution.
- [COMMAND_EXECUTION]: The skill provides shell scripts and CLI examples that perform operations on the file system and network using
git,npm, and the GitHub CLI (gh). While these are standard development tools, they are executed based on user-provided or external branch names without explicit validation.
Audit Metadata