spawn-worktree-agent

Warn

Audited by Socket on Jul 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally aligned with its purpose, but it enables high-risk autonomous real-world actions, uses permission-bypass flags, and depends on a separate unreviewed skill plus external agent CLIs. Main concern is broad delegated execution and transitive trust, not confirmed malware or credential theft.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
Jul 22, 2026, 11:18 PM
Package URL
pkg:socket/skills-sh/variableland%2Fskills%2Fspawn-worktree-agent%2F@04c24dd28c580a17ca65c1d92dbd2c97f1cd56979a7221c62d064954b1d308c4
Security Audit — socket — spawn-worktree-agent