using-git-worktrees

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes several shell commands to automate the git worktree lifecycle, including directory discovery, git configuration checks (git check-ignore), and workspace creation (git worktree add).
  • [REMOTE_CODE_EXECUTION]: The skill is designed to automatically execute code defined within a repository's configuration files. Upon creating a new worktree, it triggers package managers and test runners:
  • Executes npm install and npm test for Node.js projects.
  • Executes cargo build and cargo test for Rust projects.
  • Executes pip install, poetry install, and pytest for Python projects.
  • Executes go mod download and go test for Go projects.
  • This automation results in the execution of arbitrary scripts defined in package.json, Cargo.toml, and other project files without explicit per-execution user approval for the scripts themselves.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from CLAUDE.md to determine directory preferences, which could be exploited to influence agent behavior if the file is attacker-controlled.
  • Ingestion points: The skill reads the CLAUDE.md file using grep to find worktree directory preferences.
  • Boundary markers: None; the instructions treat the content of the file as an authoritative preference.
  • Capability inventory: The skill has the capability to execute shell commands, write to .gitignore, and commit changes to the repository.
  • Sanitization: No sanitization is performed on the data retrieved from CLAUDE.md or on the branch names before they are used in path construction for shell commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:19 AM
Security Audit — agent-trust-hub — using-git-worktrees