skills/shipshitdev/skills/worktree/Gen Agent Trust Hub

worktree

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill constructs and executes shell commands using the Bash tool, including git, sed, grep, and printf. It uses variables such as $NAME, $BRANCH, and $BASE which are derived from user input or repository metadata (branch names). This creates a risk of command injection if the agent does not strictly sanitize these inputs before execution, particularly when appending to .gitignore or executing git fetch. The skill instructions do mention sanitizing the directory name, which mitigates some path traversal risks.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the local git environment, creating a vulnerability surface.
  • Ingestion points: Data enters the agent's context through the output of commands like git symbolic-ref (current branch), git worktree list (existing worktrees), and git show-ref (ref verification). In a collaborative repository, branch names or git configuration could be manipulated by third parties.
  • Boundary markers: The skill lacks explicit instructions or delimiters (e.g., XML tags or clear 'ignore' instructions) to prevent the agent from being influenced by malicious instructions embedded in the git command outputs.
  • Capability inventory: The skill has the authority to perform network operations (git fetch), modify and commit repository files (.gitignore), and create new directories/checkouts (git worktree add).
  • Sanitization: There is a specific instruction to 'Sanitize the directory name from the branch name,' which is a positive safety control, but it does not cover all ingestion points.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 05:10 AM
Security Audit — agent-trust-hub — worktree