git-worktree

Warn

Audited by Socket on Feb 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The design aligns with a practical developer tool for managing Git worktrees with automatic setup and workflow automation. Core risks center on: (1) copying a central .env into per-worktree contexts, (2) persisting shell configuration changes, and (3) invoking external tooling (bun install) driven by conductor.json. These introduce potential data leakage, persistence concerns, and supply-chain risk. Recommend opt-in or scoped setup, explicit secrets handling, integrity verification for conductor.json and bun install, and clear documentation of what is copied and where it is stored. Overall assessment: cautious but not inherently malicious; worthy of review before broad adoption.

Confidence: 58%Severity: 55%
Audit Metadata
Analyzed At
Feb 26, 2026, 02:20 AM
Package URL
pkg:socket/skills-sh/fairchild%2Fdotclaude%2Fgit-worktree%2F@0cf1a91923a5b21683adf5f197af3af5470e006e