spawn-worktree-agent
Warn
Audited by Socket on Jul 22, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally aligned with its purpose, but it enables high-risk autonomous real-world actions, uses permission-bypass flags, and depends on a separate unreviewed skill plus external agent CLIs. Main concern is broad delegated execution and transitive trust, not confirmed malware or credential theft.
Confidence: 87%Severity: 74%
Audit Metadata