using-git-worktrees
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes several shell commands to automate the git worktree lifecycle, including directory discovery, git configuration checks (
git check-ignore), and workspace creation (git worktree add). - [REMOTE_CODE_EXECUTION]: The skill is designed to automatically execute code defined within a repository's configuration files. Upon creating a new worktree, it triggers package managers and test runners:
- Executes
npm installandnpm testfor Node.js projects. - Executes
cargo buildandcargo testfor Rust projects. - Executes
pip install,poetry install, andpytestfor Python projects. - Executes
go mod downloadandgo testfor Go projects. - This automation results in the execution of arbitrary scripts defined in
package.json,Cargo.toml, and other project files without explicit per-execution user approval for the scripts themselves. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from
CLAUDE.mdto determine directory preferences, which could be exploited to influence agent behavior if the file is attacker-controlled. - Ingestion points: The skill reads the
CLAUDE.mdfile usinggrepto find worktree directory preferences. - Boundary markers: None; the instructions treat the content of the file as an authoritative preference.
- Capability inventory: The skill has the capability to execute shell commands, write to
.gitignore, and commit changes to the repository. - Sanitization: No sanitization is performed on the data retrieved from
CLAUDE.mdor on the branch names before they are used in path construction for shell commands.
Audit Metadata