squash-merge-and-clean-up

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses git and gh (GitHub CLI) to perform repository management tasks such as merging PRs, deleting branches, and removing worktrees. These are standard operations for a developer-oriented agent.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the environment, specifically GitHub PR titles and branch names. These values are interpolated into commands (e.g., gh pr merge --subject "..."). However, the skill implements strong mitigations:
  • Human-in-the-loop: It requires explicit human confirmation via AskUserQuestion before performing any destructive or state-changing operations.
  • Plan Verification: The instructions mandate that the exact values (PR number, branch name, path) be displayed to the human for review before execution.
  • [SAFE]: The skill includes explicit instructions to avoid touching shared state or other sessions' work, adhering to a session-scoped security model.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 10:35 PM
Security Audit — agent-trust-hub — squash-merge-and-clean-up