worktrunk

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEPERSISTENCECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [PERSISTENCE]: The skill provides instructions and automation via wt config shell install to modify shell configuration files such as .bashrc, .zshrc, and PowerShell profiles. This is used to load a shell function that enables automatic directory changes when switching worktrees.
  • [COMMAND_EXECUTION]: The Worktrunk tool executes shell commands defined in configuration files through its hook and alias system. The skill documentation correctly notes that project-level commands require explicit user approval before execution to prevent unauthorized command running in newly cloned repositories.
  • [EXTERNAL_DOWNLOADS]: The skill includes instructions for downloading and installing the wt CLI and various agent plugins from GitHub and official package managers (Homebrew, Cargo, etc.). These resources are linked to the tool's official repositories.
  • [INDIRECT_PROMPT_INJECTION]: The tool ingests untrusted data from git branch names and commit messages into shell command templates. The skill provides an evidence chain for security: 1) Ingestion points are branch names and diffs; 2) Boundary markers include explicit template delimiters; 3) Capability inventory includes shell execution via hooks; 4) Sanitization is provided through built-in filters like sanitize, sanitize_db, and sanitize_hash which are recommended throughout the documentation.
  • [DYNAMIC_EXECUTION]: The shell integration uses eval for initialization, and the tool uses a Jinja-based template engine to dynamically generate shell commands. These are standard implementation patterns for CLI tool integrations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 10:19 PM
Security Audit — agent-trust-hub — worktrunk