release-cleanup

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external Pull Request metadata from GitHub to determine which branches are safe to delete. This creates an attack surface where maliciously crafted PR titles or branch names in the remote repository could attempt to influence the agent's logic. 1. Ingestion points: Data is fetched via the gh pr list command. 2. Boundary markers: The skill does not use specific delimiters for the ingested PR data, but it enforces a multi-phase verification process. 3. Capability inventory: The skill uses git push origin --delete, git branch -D, and git worktree remove for cleanup. 4. Sanitization: The skill uses jq with argument binding (--arg) to process metadata, which mitigates the risk of injection during data parsing.
  • [COMMAND_EXECUTION]: The skill performs destructive operations, including deleting remote branches and force-deleting local branches. These actions are the primary purpose of the skill and are mitigated by mandatory user confirmation and a dry-run default setting.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:19 PM
Security Audit — agent-trust-hub — release-cleanup