worktrunk
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEPERSISTENCECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [PERSISTENCE]: The skill provides instructions and automation via
wt config shell installto modify shell configuration files such as.bashrc,.zshrc, and PowerShell profiles. This is used to load a shell function that enables automatic directory changes when switching worktrees. - [COMMAND_EXECUTION]: The Worktrunk tool executes shell commands defined in configuration files through its hook and alias system. The skill documentation correctly notes that project-level commands require explicit user approval before execution to prevent unauthorized command running in newly cloned repositories.
- [EXTERNAL_DOWNLOADS]: The skill includes instructions for downloading and installing the
wtCLI and various agent plugins from GitHub and official package managers (Homebrew, Cargo, etc.). These resources are linked to the tool's official repositories. - [INDIRECT_PROMPT_INJECTION]: The tool ingests untrusted data from git branch names and commit messages into shell command templates. The skill provides an evidence chain for security: 1) Ingestion points are branch names and diffs; 2) Boundary markers include explicit template delimiters; 3) Capability inventory includes shell execution via hooks; 4) Sanitization is provided through built-in filters like
sanitize,sanitize_db, andsanitize_hashwhich are recommended throughout the documentation. - [DYNAMIC_EXECUTION]: The shell integration uses
evalfor initialization, and the tool uses a Jinja-based template engine to dynamically generate shell commands. These are standard implementation patterns for CLI tool integrations.
Audit Metadata