using-git-worktrees
Warn
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute a variety of system and development commands, including
git,npm,cargo,pip,poetry, andgo. It automatically runs project test suites (e.g.,npm test,pytest) and build commands (e.g.,cargo build) based on the detected project type. - [EXTERNAL_DOWNLOADS]: The skill triggers the download and installation of external software packages using standard package managers. It executes commands like
npm install,pip install -r requirements.txt,poetry install, andgo mod downloadwhich fetch code from public registries based on configuration files in the local workspace. - [DATA_EXPOSURE]: The skill accesses the local filesystem at
~/.config/superpowers/worktrees/to check for legacy configuration paths. - [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection as it processes untrusted local data to determine its execution path.
- Ingestion points: Local repository files including
package.json,Cargo.toml,requirements.txt,pyproject.toml, andgo.mod(SKILL.md). - Boundary markers: No specific delimiters or warnings are used to prevent the agent from following instructions potentially embedded within these project files.
- Capability inventory: The agent has the capability to perform shell command execution, file system writes (via
.gitignoremodification), and network requests (via package managers). - Sanitization: No validation or sanitization of the contents of the ingested files is performed before they are used to trigger command execution.
Audit Metadata