daft-worktree-workflow

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The daft.yml configuration file includes hooks that download and execute installation scripts for Homebrew (raw.githubusercontent.com/Homebrew/install) and Mise (mise.run). Additionally, the README provides a PowerShell installation command referencing the official GitHub repository for the tool. These sources are well-known and reputable within the developer community.\n- [COMMAND_EXECUTION]: The toolkit is designed to automate Git worktree management and development environment setup by executing shell commands defined in daft.yml hooks. The system includes a built-in trust mechanism (daft hooks trust) that prevents the automatic execution of repository-provided scripts without explicit user consent.\n- [SAFE]: No malicious patterns, prompt injections, credential theft, or unauthorized data exfiltration attempts were detected during the analysis of the skill instructions or the provided source code snippets.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 12:36 PM