release-cleanup
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external Pull Request metadata from GitHub to determine which branches are safe to delete. This creates an attack surface where maliciously crafted PR titles or branch names in the remote repository could attempt to influence the agent's logic. 1. Ingestion points: Data is fetched via the
gh pr listcommand. 2. Boundary markers: The skill does not use specific delimiters for the ingested PR data, but it enforces a multi-phase verification process. 3. Capability inventory: The skill usesgit push origin --delete,git branch -D, andgit worktree removefor cleanup. 4. Sanitization: The skill usesjqwith argument binding (--arg) to process metadata, which mitigates the risk of injection during data parsing. - [COMMAND_EXECUTION]: The skill performs destructive operations, including deleting remote branches and force-deleting local branches. These actions are the primary purpose of the skill and are mitigated by mandatory user confirmation and a dry-run default setting.
Audit Metadata