wspace
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for the agent to perform development tasks by executing shell commands and local CLI tools.
- Evidence: The skill utilizes
git,gh(GitHub CLI),jq, and a customwspaceutility to manage repositories and automate the 'Goal loop' and 'Pipeline' workflows defined inSKILL.mdandreferences/COMMANDS.md. - [SAFE]: The skill implements a surface for indirect prompt injection by processing external GitHub issue data, but employs structured data handling to mitigate risk.
- Ingestion points: The
SCANphase inSKILL.mdfetches issue metadata (number, title, repository) from GitHub usinggh search issues. - Boundary markers: The process uses the
--jsonflag to ensure data is returned in a structured format rather than raw text. - Capability inventory: The agent performs local file system operations, Git management, and PR creation based on the ingested data.
- Sanitization: The use of
jqto extract specific fields (number,repository) ensures that only expected data influences downstream command execution, limiting the impact of malicious content in issue titles. - [SAFE]: The skill handles sensitive environment variables using local-only synchronization practices.
- Evidence: The
wspace env synccommand manages project secrets by copying them from a central, gitignoredsecrets/directory to specific worktrees. This approach avoids hardcoded credentials and prevents secrets from being committed to version control, which is an established safe practice.
Audit Metadata