clean-branch
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses shell-based git commands to fetch repository status, inspect commit history, and delete local branches.
- [EXTERNAL_DOWNLOADS]: The skill synchronization logic relies on
git fetch --all --prune, which connects to the user's configured remote repositories to retrieve the latest state. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted metadata from the repository, including branch names and commit summaries, which could be crafted to contain malicious instructions.
- Ingestion points: Data is ingested from the output of
git branchandgit logcommands. - Boundary markers: Present; the skill provides a clear reporting phase in Step 5 that separates the analysis from execution, requiring explicit user input.
- Capability inventory: The skill possesses the ability to delete local filesystem references (branches) via
git branch -d. - Sanitization: Relies on user verification of the generated branch report rather than programmatic filtering of branch metadata.
Audit Metadata