skills/letstri/skills/cleanup/Gen Agent Trust Hub

cleanup

Pass

Audited by Gen Agent Trust Hub on Oct 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to read and prioritize instructions from files within the repository (such as CLAUDE.md and AGENTS.md), explicitly stating they "outrank this skill." This creates an attack surface where malicious instructions embedded in a project's documentation or rule files could override the agent's intended behavior.
  • Ingestion points: Reads CLAUDE.md, AGENTS.md, and any files they index within the repository.
  • Boundary markers: Absent; no instructions are provided to the agent to treat external content as untrusted or to ignore embedded instructions.
  • Capability inventory: The skill has the ability to perform file edits, execute shell commands (git, gh, pnpm, tsc), and spawn subagents to process large diffs.
  • Sanitization: Absent; there is no validation or filtering of the content read from the repository files.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes pnpm dlx to download and execute knip and jscpd at runtime. These are established tools in the JavaScript ecosystem used for identifying unused code and duplication.
  • [COMMAND_EXECUTION]: The skill executes various shell commands to analyze the repository state, including git (fetch, diff, status, merge-base), gh (GitHub CLI to view PR details), pnpm (for tool execution), and tsc (TypeScript compiler for type checking). It also invokes project-specific linters.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 9, 2026, 10:30 AM