recursive-worktree

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute repository-specific setup commands, including npm install, cargo build, pip install -r requirements.txt, go mod download, mvn compile, ./gradlew compileJava, and dotnet restore based on the detected project type.
  • [DYNAMIC_EXECUTION]: The skill executes a project-local Python script located at ./.recursive/scripts/recursive-router-probe.py to refresh local discovery state and determine routing policies.
  • [INDIRECT_PROMPT_INJECTION]: The agent's routing decisions and setup behavior are governed by the contents of local configuration files (.recursive/config/recursive-router.json and recursive-router-discovered.json). Malicious modifications to these files could influence the agent's subsequent actions or model selection.
  • Ingestion points: Reads routing policy and discovery inventory from /.recursive/config/recursive-router.json and /.recursive/config/recursive-router-discovered.json (SKILL.md).
  • Boundary markers: None; the agent is instructed to "honor the routed policy" immediately after reading the files.
  • Capability inventory: Git worktree management, package installation via multiple package managers, and Python script execution.
  • Sanitization: No evidence of schema validation or sanitization is provided for the JSON configuration files before they are used to determine routing logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 03:59 AM