finishing-a-development-branch
Pass
Audited by Gen Agent Trust Hub on May 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements standard development practices. All commands (git, gh, npm, cargo, pytest, go) are appropriate for the stated purpose of branch management and testing.
- [SAFE]: Indirect Prompt Injection Surface: The skill processes external data such as test results and commit messages.
- Ingestion points: Test failure outputs in Step 1 and commit lists/branch names in Step 4 are processed from the local environment into the agent's context.
- Boundary markers: Absent; the agent is instructed to show or use the data directly.
- Capability inventory: Shell execution of git, gh, and language-specific test runners as defined in SKILL.md.
- Sanitization: Absent; the skill relies on the standard output of these tools.
- Analysis: This represents a normal development workflow surface with no identified malicious exploitation patterns.
Audit Metadata