git-worktree-manager

Fail

Audited by Socket on Feb 21, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Destructive bash command detected (rm -rf, chmod 777) All findings: [CRITICAL] command_injection: Destructive bash command detected (rm -rf, chmod 777) (CI004) [AITech 9.1.4] [CRITICAL] command_injection: Destructive bash command detected (rm -rf, chmod 777) (CI004) [AITech 9.1.4] [CRITICAL] command_injection: Destructive bash command detected (rm -rf, chmod 777) (CI004) [AITech 9.1.4] BENIGN: The content is a comprehensive documentation guide for Git worktree management with consistent scope and no code that performs data reads/writes, network calls, or credential handling. It does not introduce unexpected capabilities or risky data flows. LLM verification: This skill is documentation for git worktree management and is functionally consistent with its stated purpose. I did not find code that intentionally exfiltrates data, installs remote payloads, or performs stealthy malicious actions. However, multiple examples include unguarded destructive commands (rm -rf, git worktree remove --force) and broad removal loops that pose an accidental data-loss risk. Treat the examples as potentially dangerous to copy-paste without reviewing paths and adding safe

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 21, 2026, 09:23 AM
Package URL
pkg:socket/skills-sh/d-o-hub%2Frust-self-learning-memory%2Fgit-worktree-manager%2F@09306ccc3cf9a7a8dfaacda69984377282edbbee