mcp-attribution-worktree

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses several command-line tools to perform its tasks. It executes curl to interact with a local Report API hosted at http://127.0.0.1:5174. It also uses the gh (GitHub CLI) for issue tracking and PR management (e.g., gh issue create, gh pr create) and wt (Worktrunk) for creating and managing isolated worktrees. These operations are scoped to the development environment and the TencentCloudBase/CloudBase-MCP repository.
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through its ingestion of external data.
  • Ingestion points: The agent fetches issue details, user notes, and conversation traces from the local Report API (references/report-api-workflow.md).
  • Boundary markers: There are no explicit instructions or XML-style delimiters defined to isolate the untrusted run traces or evaluation results from the agent's core instructions.
  • Capability inventory: The skill has the capability to write to the local API, create GitHub issues and PRs, and modify the filesystem through Worktrunk worktrees.
  • Sanitization: The instructions do not specify sanitization or filtering protocols for the data retrieved from the Report API, though they do mandate a 'closure preflight' and human-style auditing of evidence before resolving issues.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 09:35 AM
Security Audit — agent-trust-hub — mcp-attribution-worktree