clean-branch

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from issues, pull requests, and repository files to determine the scope and logic of feature extraction. While the skill includes instructions for manual hunk selection and verification, it lacks explicit boundary markers or sanitization for this ingested content.
  • Ingestion points: The identification phase in SKILL.md relies on data from relevant issues and PRs.
  • Boundary markers: No specific delimiters or instructions to ignore instructions embedded in data are present.
  • Capability inventory: The skill uses git commands and executes 'relevant feature tests' and 'repository-required checks' as part of its verification process.
  • Sanitization: No specific filtering or sanitization of the external input is described.
  • [COMMAND_EXECUTION]: The skill uses shell-based git commands, including 'git worktree' and the 'git-wt' utility, to perform its core repository management tasks. These are standard operations for its stated purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 03:28 AM
Security Audit — agent-trust-hub — clean-branch