worktree-manager-skill
Fail
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: HIGHCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTION
Full Analysis
- [PRIVILEGE_ESCALATION]: The skill mandates the use of the
--dangerously-skip-permissionsflag when launching sub-agents in worktrees. This configuration explicitly disables the AI platform's security guardrails that normally require human approval for sensitive operations like file system modifications and shell command execution, granting the sub-agents full autonomous control over the user's environment. - [COMMAND_EXECUTION]: Helper scripts including
scripts/launch-agent.sh,scripts/register.sh, andscripts/cleanup.shinterpolate variables such as$WORKTREE_PATH,$BRANCH, and$PROJECTdirectly into shell commands, AppleScripts, and heredocs. Since these variables are derived from external git metadata that can be influenced by a repository's content or branch names, an attacker could craft malicious branch names or repository titles to execute arbitrary commands on the user's machine. - [DYNAMIC_CONTEXT_INJECTION]: The
SKILL.mdfile utilizes the!commandsyntax to automatically execute shell commands likegit status,git worktree list, andcatto display system state. This provides an execution surface that runs silently in the background whenever the skill is loaded or referenced by the agent. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the local environment (e.g., git status, branch names, and PR info via the
ghCLI) to generate task descriptions and registry entries. - Ingestion points: Shell command outputs in
SKILL.md(!git status) and status monitoring inscripts/status.sh(gh pr list). - Boundary markers: Missing; task descriptions are written to
WORKTREE_TASK.mdwithout delimiters or warnings to the agent regarding potential instructions embedded in the project metadata. - Capability inventory: Significant; includes file writing, process termination (
kill -9), directory removal (rm -rf), and launching new terminal sessions. - Sanitization: Incomplete; while some scripts slugify branch names, many variables remain unescaped during interpolation into shell execution contexts.
Recommendations
- AI detected serious security threats
Audit Metadata