worktree-manager

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core worktree-management behavior is coherent and mostly local, with no clear malicious exfiltration path or untrusted installer chain. Risk is elevated because the skill goes beyond simple worktree management to launch autonomous Claude Code agents, recommends --dangerously-skip-permissions, and may expose copied .env content to those agents while helper-script behavior remains unreviewed.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Apr 4, 2026, 05:29 AM
Package URL
pkg:socket/skills-sh/zircote%2Fclaude-spec%2Fworktree-manager%2F@21850408fe9cb29d514e605880055190b9aab8e3
Security Audit — socket — worktree-manager