worktree

Warn

Audited by Socket on Aug 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

BENIGN in purpose and data flow: the skill’s capabilities match isolated Git worktree management, and it does not route data or credentials to external services. However, it materially depends on a nonstandard `doctrine` executable with unclear public provenance and no visible registry-backed install or release verification, so the overall classification is SUSPICIOUS/HIGH-RISK from supply-chain trust rather than confirmed malware.

Confidence: 88%Severity: 78%
Audit Metadata
Analyzed At
Aug 16, 2026, 01:24 PM
Package URL
pkg:socket/skills-sh/davidlee%2Fdoctrine%2Fworktree%2F@35ddd5eaf9687e25dee4f2e8bea410f07360772629277a2601a7eeb9ff684919
Security Audit — socket — worktree