skills/wazootech/workspace-cli/wspace/Gen Agent Trust Hub

wspace

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for the agent to perform development tasks by executing shell commands and local CLI tools.
  • Evidence: The skill utilizes git, gh (GitHub CLI), jq, and a custom wspace utility to manage repositories and automate the 'Goal loop' and 'Pipeline' workflows defined in SKILL.md and references/COMMANDS.md.
  • [SAFE]: The skill implements a surface for indirect prompt injection by processing external GitHub issue data, but employs structured data handling to mitigate risk.
  • Ingestion points: The SCAN phase in SKILL.md fetches issue metadata (number, title, repository) from GitHub using gh search issues.
  • Boundary markers: The process uses the --json flag to ensure data is returned in a structured format rather than raw text.
  • Capability inventory: The agent performs local file system operations, Git management, and PR creation based on the ingested data.
  • Sanitization: The use of jq to extract specific fields (number, repository) ensures that only expected data influences downstream command execution, limiting the impact of malicious content in issue titles.
  • [SAFE]: The skill handles sensitive environment variables using local-only synchronization practices.
  • Evidence: The wspace env sync command manages project secrets by copying them from a central, gitignored secrets/ directory to specific worktrees. This approach avoids hardcoded credentials and prevents secrets from being committed to version control, which is an established safe practice.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 11:58 PM
Security Audit — agent-trust-hub — wspace