git-worktree-manager
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The Python scripts
scripts/worktree_manager.py,scripts/port_allocator.py, andscripts/worktree_validator.pyutilize thesubprocess.runfunction to executegitcommands. Technical review confirms these calls use argument lists rather than shell strings, which mitigates risk of command injection from external inputs like branch names. - [CREDENTIALS_UNSAFE]: The skill's setup logic involves copying
.envfiles from the main repository to new worktree directories to maintain environment parity. While these files often contain sensitive secrets, the operation is restricted to the local filesystem and is a standard requirement for development workflows. - [EXTERNAL_DOWNLOADS]: The documentation in
references/setup-and-ports.mdincludes a setup script that triggers standard package managers (such aspnpm,npm,yarn, andpip) to install project dependencies. These operations target official package registries and are triggered by the presence of standard lockfiles.
Audit Metadata