sweep
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a structured cleanup workflow (SCAN → ANALYZE → CATEGORIZE → PROPOSE → EXECUTE → VERIFY) with a strong emphasis on evidence-based decision-making and safety. It explicitly warns against aggressive pruning and prioritizes reversibility.
- [SAFE]: Comprehensive safety boundaries are established in
SKILL.mdandreference/exclusion-patterns.md. The skill is forbidden from deleting sensitive files (e.g.,.env*,LICENSE*,*.local, lockfiles) and critical paths without extra verification. It also mandates creating a backup branch before any deletions. - [SAFE]: The skill relies on established open-source static analysis tools for multiple ecosystems, including
knip(JS/TS),vulture(Python),staticcheck(Go), andcargo udeps(Rust). It treats tool output as evidence rather than absolute authority, requiring cross-verification from at least two independent signals. - [SAFE]: Instructions include clear guardrails against common cleanup risks, referencing historical incidents like the Knight Capital loss to emphasize the danger of stale feature flags and 'zombie' code.
- [INDIRECT_PROMPT_INJECTION]: While the skill ingests and analyzes source code (external data), it mitigates indirect prompt injection risks by requiring static tool confirmation for all LLM findings and maintaining a strict human-in-the-loop verification process before execution.
Audit Metadata