using-git-worktrees

Warn

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a variety of system and development commands, including git, npm, cargo, pip, poetry, and go. It automatically runs project test suites (e.g., npm test, pytest) and build commands (e.g., cargo build) based on the detected project type.
  • [EXTERNAL_DOWNLOADS]: The skill triggers the download and installation of external software packages using standard package managers. It executes commands like npm install, pip install -r requirements.txt, poetry install, and go mod download which fetch code from public registries based on configuration files in the local workspace.
  • [DATA_EXPOSURE]: The skill accesses the local filesystem at ~/.config/superpowers/worktrees/ to check for legacy configuration paths.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection as it processes untrusted local data to determine its execution path.
  • Ingestion points: Local repository files including package.json, Cargo.toml, requirements.txt, pyproject.toml, and go.mod (SKILL.md).
  • Boundary markers: No specific delimiters or warnings are used to prevent the agent from following instructions potentially embedded within these project files.
  • Capability inventory: The agent has the capability to perform shell command execution, file system writes (via .gitignore modification), and network requests (via package managers).
  • Sanitization: No validation or sanitization of the contents of the ingested files is performed before they are used to trigger command execution.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 22, 2026, 12:14 PM
Security Audit — agent-trust-hub — using-git-worktrees