worktree
Warn
Audited by Socket on Aug 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
BENIGN in purpose and data flow: the skill’s capabilities match isolated Git worktree management, and it does not route data or credentials to external services. However, it materially depends on a nonstandard `doctrine` executable with unclear public provenance and no visible registry-backed install or release verification, so the overall classification is SUSPICIOUS/HIGH-RISK from supply-chain trust rather than confirmed malware.
Confidence: 88%Severity: 78%
Audit Metadata