ship

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/ship-worktree.sh

No clear indicators of covert malware (exfiltration, persistence, cryptomining) are present in this snippet. However, the cleanup path can execute an arbitrary shell command sourced from a JSON state field (isolatedEnv.teardownCommand) using bash -lc, which constitutes a high-impact RCE/sabotage risk if the state file can be tampered with or is not strictly trusted. Apart from that, the script mainly performs local Git worktree/branch management with some safety checks.

Confidence: 70%Severity: 68%
Audit Metadata
Analyzed At
Apr 14, 2026, 09:31 AM
Package URL
pkg:socket/skills-sh/inkeep%2Fteam-skills%2Fship%2F@baaba7c5626f579a6a50d4835fbd804ee46d25c9