recursive-worktree
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute repository-specific setup commands, including
npm install,cargo build,pip install -r requirements.txt,go mod download,mvn compile,./gradlew compileJava, anddotnet restorebased on the detected project type. - [DYNAMIC_EXECUTION]: The skill executes a project-local Python script located at
./.recursive/scripts/recursive-router-probe.pyto refresh local discovery state and determine routing policies. - [INDIRECT_PROMPT_INJECTION]: The agent's routing decisions and setup behavior are governed by the contents of local configuration files (
.recursive/config/recursive-router.jsonandrecursive-router-discovered.json). Malicious modifications to these files could influence the agent's subsequent actions or model selection. - Ingestion points: Reads routing policy and discovery inventory from
/.recursive/config/recursive-router.jsonand/.recursive/config/recursive-router-discovered.json(SKILL.md). - Boundary markers: None; the agent is instructed to "honor the routed policy" immediately after reading the files.
- Capability inventory: Git worktree management, package installation via multiple package managers, and Python script execution.
- Sanitization: No evidence of schema validation or sanitization is provided for the JSON configuration files before they are used to determine routing logic.
Audit Metadata