clean-branch

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses shell-based git commands to fetch repository status, inspect commit history, and delete local branches.
  • [EXTERNAL_DOWNLOADS]: The skill synchronization logic relies on git fetch --all --prune, which connects to the user's configured remote repositories to retrieve the latest state.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted metadata from the repository, including branch names and commit summaries, which could be crafted to contain malicious instructions.
  • Ingestion points: Data is ingested from the output of git branch and git log commands.
  • Boundary markers: Present; the skill provides a clear reporting phase in Step 5 that separates the analysis from execution, requiring explicit user input.
  • Capability inventory: The skill possesses the ability to delete local filesystem references (branches) via git branch -d.
  • Sanitization: Relies on user verification of the generated branch report rather than programmatic filtering of branch metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 11:12 AM
Security Audit — agent-trust-hub — clean-branch