using-git-worktrees

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues detected. The skill provides instructional guidance on using standard Git commands and platform-specific worktree features.
  • [PROMPT_INJECTION]: A prompt injection pattern was identified in references/evals.yaml. This is a false positive for malicious intent, as the pattern is part of a security test case designed to verify that the agent correctly refuses to bypass safety filters and execute dangerous commands like rm -rf when pressured.
  • [COMMAND_EXECUTION]: The skill mentions the execution of a local feedback script (utilities/skill-builder/scripts/record_skill_feedback.py) and standard Git CLI tools. These are legitimate operations required for the skill's functionality and performance tracking within a controlled environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 01:14 PM
Security Audit — agent-trust-hub — using-git-worktrees