workspace-isolation

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill automates environment setup by invoking standard package managers including npm, cargo, pip, poetry, and go. These tools interact with official package registries to download project dependencies.
  • [COMMAND_EXECUTION]: The skill utilizes shell commands to manage Git worktree operations, verify directory structures, and execute project-specific test suites such as pytest or npm test.
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves configuration preferences from a project-level file (CLAUDE.md).
  • Ingestion points: CLAUDE.md (referenced via grep).
  • Boundary markers: No explicit delimiters or boundary warnings are used when processing the file content.
  • Capability inventory: Executes shell commands for directory creation, path navigation, Git operations, and dependency installation.
  • Sanitization: The content retrieved from the configuration file is used directly in path construction without explicit validation or escaping.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 03:17 AM
Security Audit — agent-trust-hub — workspace-isolation