workspace-isolation
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill automates environment setup by invoking standard package managers including npm, cargo, pip, poetry, and go. These tools interact with official package registries to download project dependencies.
- [COMMAND_EXECUTION]: The skill utilizes shell commands to manage Git worktree operations, verify directory structures, and execute project-specific test suites such as pytest or npm test.
- [INDIRECT_PROMPT_INJECTION]: The skill retrieves configuration preferences from a project-level file (CLAUDE.md).
- Ingestion points: CLAUDE.md (referenced via grep).
- Boundary markers: No explicit delimiters or boundary warnings are used when processing the file content.
- Capability inventory: Executes shell commands for directory creation, path navigation, Git operations, and dependency installation.
- Sanitization: The content retrieved from the configuration file is used directly in path construction without explicit validation or escaping.
Audit Metadata