clean

Pass

Audited by Gen Agent Trust Hub on Jun 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill performs file deletion on the local filesystem as its primary function. Safety protocols are integrated: The agent must verify if the project is under version control and check for uncommitted changes before proceeding. The workflow requires a mandatory user confirmation step after presenting a list of files intended for deletion. Explicit rules preserve source code and configuration files.
  • [PROMPT_INJECTION]: The skill contains a surface for indirect prompt injection by reading project-specific metadata. 1. Ingestion points: The skill reads .ai-memory.md from the project root and scans local directory structures. 2. Boundary markers: No specific delimiters are defined to separate instructions from data. 3. Capability inventory: The agent has the ability to delete files and modify the .gitignore configuration. 4. Sanitization: No automated sanitization is present; however, the human-in-the-loop confirmation requirement is the primary control.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 25, 2026, 09:59 PM
Security Audit — agent-trust-hub — clean