worktree-rebase-merge

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses a Python helper script (scripts/collect-integration-facts.py) and agent instructions to execute standard Git commands such as git status, git rebase, and git merge. These operations are used to automate local development workflows. The Python script correctly uses list-based arguments for subprocess.run to prevent shell-based command injection.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from the local Git repository, including commit logs, branch names, and worktree status. While this creates a surface for indirect prompt injection from potentially malicious repository content, the skill uses structured JSON output and internal validation to mitigate risks.
  • Ingestion points: Git metadata, commit messages, and repository file contents processed in scripts/collect-integration-facts.py and referenced workflow documents.
  • Boundary markers: Findings are returned via structured JSON for the agent to process; however, the skill does not explicitly define delimiters for the agent when it manually interprets Git log output.
  • Capability inventory: The skill performs file system modifications (rebase, merge) and network operations (querying remote HEAD via ls-remote to the user's configured remote).
  • Sanitization: Input branch names are validated via git check-ref-format before usage. The helper script uses SHA-256 hashing for content tracking instead of passing full file contents into the agent's context, reducing exposure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 02:46 AM
Security Audit — agent-trust-hub — worktree-rebase-merge