parallel-worktrees

Warn

Audited by Socket on Jun 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

Mostly a benign workflow guide for git worktrees and PR coordination, but it includes a notable transitive-install trust issue: the published skill metadata points to Codervisor while setup installs a different repo (onsager-ai/dev-skills). Core git/GitHub capabilities are proportionate to the stated purpose, with moderate risk from third-party skill installation and externally visible GitHub actions.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 12, 2026, 10:43 PM
Package URL
pkg:socket/skills-sh/onsager-ai%2Fdev-skills%2Fparallel-worktrees%2F@69d797ee435cb7001fe00b0b20581ef0f4f4119330df8ae5f814f2fff69f1233
Security Audit — socket — parallel-worktrees