create-worktree

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core purpose aligns with git worktree creation, but the skill’s footprint expands into executing project-configured shell commands and launching an unattended Claude session with safety prompts disabled. There is no clear credential exfiltration or malicious data routing, but the bypassed approvals and autonomous follow-on actions make the skill high-risk relative to its stated convenience function.

Confidence: 88%Severity: 71%
Audit Metadata
Analyzed At
Sep 16, 2026, 09:30 PM
Package URL
pkg:socket/skills-sh/coalesce-labs%2Fcatalyst-dev-skills%2Fcreate-worktree%2F@16f757155066537224a22c85647859b8c96eb21b1d7f97b65db897c21b55599c
Security Audit — socket — create-worktree