git-worktree-manager
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The scripts utilize
subprocess.runto perform Git operations and dependency installations. Analysis ofscripts/worktree_manager.pyandscripts/worktree_cleanup.pyconfirms that these commands are executed as lists of arguments rather than shell strings, preventing common shell injection vectors. - [EXTERNAL_DOWNLOADS]: The manager script facilitates dependency installation using standard package managers such as npm, pip, yarn, and bun. These downloads are performed from official registries based on local lockfile configuration, representing expected functional behavior for a development tool.
- [INDIRECT_PROMPT_INJECTION]: The skill includes an attack surface for data ingestion via JSON input but implements sufficient controls to prevent exploitation.
- Ingestion points: The
load_json_inputfunction inscripts/worktree_manager.pyandscripts/worktree_cleanup.pyreads data from stdin or specified files. - Boundary markers: The use of JSON structure and specific CLI argument definitions provides clear data boundaries.
- Capability inventory: Git worktree management, local file system writes for port mapping, environment file synchronization, and local dependency installation.
- Sanitization: Inputs are processed through explicit type conversion and
pathlib.Path.resolve(), ensuring that paths and variables are handled as data rather than executable instructions.
Audit Metadata