worktree-rebase-merge
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses a Python helper script (
scripts/collect-integration-facts.py) and agent instructions to execute standard Git commands such asgit status,git rebase, andgit merge. These operations are used to automate local development workflows. The Python script correctly uses list-based arguments forsubprocess.runto prevent shell-based command injection. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from the local Git repository, including commit logs, branch names, and worktree status. While this creates a surface for indirect prompt injection from potentially malicious repository content, the skill uses structured JSON output and internal validation to mitigate risks.
- Ingestion points: Git metadata, commit messages, and repository file contents processed in
scripts/collect-integration-facts.pyand referenced workflow documents. - Boundary markers: Findings are returned via structured JSON for the agent to process; however, the skill does not explicitly define delimiters for the agent when it manually interprets Git log output.
- Capability inventory: The skill performs file system modifications (rebase, merge) and network operations (querying remote HEAD via
ls-remoteto the user's configured remote). - Sanitization: Input branch names are validated via
git check-ref-formatbefore usage. The helper script uses SHA-256 hashing for content tracking instead of passing full file contents into the agent's context, reducing exposure.
Audit Metadata