worktree-manager-skill

Fail

Audited by Gen Agent Trust Hub on Oct 8, 2026

Risk Level: HIGHCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill mandates the use of the --dangerously-skip-permissions flag when launching sub-agents in worktrees. This configuration explicitly disables the AI platform's security guardrails that normally require human approval for sensitive operations like file system modifications and shell command execution, granting the sub-agents full autonomous control over the user's environment.
  • [COMMAND_EXECUTION]: Helper scripts including scripts/launch-agent.sh, scripts/register.sh, and scripts/cleanup.sh interpolate variables such as $WORKTREE_PATH, $BRANCH, and $PROJECT directly into shell commands, AppleScripts, and heredocs. Since these variables are derived from external git metadata that can be influenced by a repository's content or branch names, an attacker could craft malicious branch names or repository titles to execute arbitrary commands on the user's machine.
  • [DYNAMIC_CONTEXT_INJECTION]: The SKILL.md file utilizes the !command syntax to automatically execute shell commands like git status, git worktree list, and cat to display system state. This provides an execution surface that runs silently in the background whenever the skill is loaded or referenced by the agent.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the local environment (e.g., git status, branch names, and PR info via the gh CLI) to generate task descriptions and registry entries.
  • Ingestion points: Shell command outputs in SKILL.md (!git status) and status monitoring in scripts/status.sh (gh pr list).
  • Boundary markers: Missing; task descriptions are written to WORKTREE_TASK.md without delimiters or warnings to the agent regarding potential instructions embedded in the project metadata.
  • Capability inventory: Significant; includes file writing, process termination (kill -9), directory removal (rm -rf), and launching new terminal sessions.
  • Sanitization: Incomplete; while some scripts slugify branch names, many variables remain unescaped during interpolation into shell execution contexts.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Oct 8, 2026, 09:54 PM