using-git-worktrees
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues detected. The skill provides instructional guidance on using standard Git commands and platform-specific worktree features.
- [PROMPT_INJECTION]: A prompt injection pattern was identified in references/evals.yaml. This is a false positive for malicious intent, as the pattern is part of a security test case designed to verify that the agent correctly refuses to bypass safety filters and execute dangerous commands like rm -rf when pressured.
- [COMMAND_EXECUTION]: The skill mentions the execution of a local feedback script (utilities/skill-builder/scripts/record_skill_feedback.py) and standard Git CLI tools. These are legitimate operations required for the skill's functionality and performance tracking within a controlled environment.
Audit Metadata