git-worktree-manager

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The Python scripts scripts/worktree_manager.py, scripts/port_allocator.py, and scripts/worktree_validator.py utilize the subprocess.run function to execute git commands. Technical review confirms these calls use argument lists rather than shell strings, which mitigates risk of command injection from external inputs like branch names.
  • [CREDENTIALS_UNSAFE]: The skill's setup logic involves copying .env files from the main repository to new worktree directories to maintain environment parity. While these files often contain sensitive secrets, the operation is restricted to the local filesystem and is a standard requirement for development workflows.
  • [EXTERNAL_DOWNLOADS]: The documentation in references/setup-and-ports.md includes a setup script that triggers standard package managers (such as pnpm, npm, yarn, and pip) to install project dependencies. These operations target official package registries and are triggered by the presence of standard lockfiles.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 02:16 AM
Security Audit — agent-trust-hub — git-worktree-manager