worktree

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill is coherently aligned with its stated purpose: it automates the creation of git worktrees using standard git commands, derives branch names from user input with conventions, sets up submodule scopes, and provides output guidance. It does not appear to download-unverified binaries, require sensitive credentials, or exfiltrate data. The primary security consideration is potential command-injection risk from user input shaping branch names; this is a plausible but manageable risk given proper input sanitization and constrained command surface. Overall, the footprint is benign and proportionate to the described feature-development workflow.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 07:58 AM
Package URL
pkg:socket/skills-sh/JHostalek%2Fdotclaude%2Fworktree%2F@c28b9a580b2a6c33dbdd406059d1591a647a0df2
Security Audit — socket — worktree