git-worktrees
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The instructions in the 'How to Create Worktree' section direct the agent to automatically execute shell commands for package management (e.g.,
npm install,pip install,cargo build) based on files detected in a new worktree directory. - [REMOTE_CODE_EXECUTION]: By instructing the agent to fetch remote branches (including external pull requests) and immediately run installation scripts without user approval, the skill enables the execution of arbitrary code provided by untrusted sources via package manager lifecycle hooks (such as Node.js
postinstall). - [INDIRECT_PROMPT_INJECTION]: The skill exhibits an unsafe processing pipeline where data from an external repository is ingested and used to trigger command execution without boundary markers or content verification.
- Ingestion points: Configuration files located in the root of new worktrees (
package.json,Gemfile,requirements.txt, etc.) in theSKILL.mdinstruction block. - Boundary markers: None provided; there are no instructions for the agent to verify the safety of repository content before execution.
- Capability inventory: Full shell command execution for git and multiple package manager ecosystems.
- Sanitization: The instructions explicitly remove the human-in-the-loop safety check by directing the agent to run setup commands "without prompting" the user for confirmation.
Recommendations
- AI detected serious security threats
Audit Metadata