mcp-attribution-worktree
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses several command-line tools to perform its tasks. It executes
curlto interact with a local Report API hosted athttp://127.0.0.1:5174. It also uses thegh(GitHub CLI) for issue tracking and PR management (e.g.,gh issue create,gh pr create) andwt(Worktrunk) for creating and managing isolated worktrees. These operations are scoped to the development environment and theTencentCloudBase/CloudBase-MCPrepository. - [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through its ingestion of external data.
- Ingestion points: The agent fetches issue details, user notes, and conversation traces from the local Report API (
references/report-api-workflow.md). - Boundary markers: There are no explicit instructions or XML-style delimiters defined to isolate the untrusted run traces or evaluation results from the agent's core instructions.
- Capability inventory: The skill has the capability to write to the local API, create GitHub issues and PRs, and modify the filesystem through Worktrunk worktrees.
- Sanitization: The instructions do not specify sanitization or filtering protocols for the data retrieved from the Report API, though they do mandate a 'closure preflight' and human-style auditing of evidence before resolving issues.
Audit Metadata