create-worktree
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core purpose aligns with git worktree creation, but the skill’s footprint expands into executing project-configured shell commands and launching an unattended Claude session with safety prompts disabled. There is no clear credential exfiltration or malicious data routing, but the bypassed approvals and autonomous follow-on actions make the skill high-risk relative to its stated convenience function.
Confidence: 88%Severity: 71%
Audit Metadata