git-worktree-manager

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The scripts utilize subprocess.run to perform Git operations and dependency installations. Analysis of scripts/worktree_manager.py and scripts/worktree_cleanup.py confirms that these commands are executed as lists of arguments rather than shell strings, preventing common shell injection vectors.
  • [EXTERNAL_DOWNLOADS]: The manager script facilitates dependency installation using standard package managers such as npm, pip, yarn, and bun. These downloads are performed from official registries based on local lockfile configuration, representing expected functional behavior for a development tool.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes an attack surface for data ingestion via JSON input but implements sufficient controls to prevent exploitation.
  • Ingestion points: The load_json_input function in scripts/worktree_manager.py and scripts/worktree_cleanup.py reads data from stdin or specified files.
  • Boundary markers: The use of JSON structure and specific CLI argument definitions provides clear data boundaries.
  • Capability inventory: Git worktree management, local file system writes for port mapping, environment file synchronization, and local dependency installation.
  • Sanitization: Inputs are processed through explicit type conversion and pathlib.Path.resolve(), ensuring that paths and variables are handled as data rather than executable instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 01:33 PM