super-worktree

Warn

Audited by Socket on May 7, 2026

3 alerts found:

Anomalyx3
AnomalyLOW
files/skills/super-worktree/SKILL.md

SUSPICIOUS: the skill’s main capabilities mostly match its stated purpose, but it normalizes copying sensitive credential files into worktrees, supports arbitrary hook execution, and is distributed via transitive skill-install mechanisms. There is no clear evidence of external exfiltration or hidden malware, so this is better classified as a high-risk local automation skill than confirmed malicious content.

Confidence: 84%Severity: 63%
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s main capabilities mostly match its stated purpose, but it normalizes copying sensitive credential files into worktrees, supports arbitrary hook execution, and is distributed via transitive skill-install mechanisms. There is no clear evidence of external exfiltration or hidden malware, so this is better classified as a high-risk local automation skill than confirmed malicious content.

Confidence: 84%Severity: 63%
AnomalyLOW
skills/super-worktree/SKILL.md

SUSPICIOUS: the skill’s main capabilities mostly match its stated purpose, but it normalizes copying sensitive credential files into worktrees, supports arbitrary hook execution, and is distributed via transitive skill-install mechanisms. There is no clear evidence of external exfiltration or hidden malware, so this is better classified as a high-risk local automation skill than confirmed malicious content.

Confidence: 84%Severity: 63%
Audit Metadata
Analyzed At
May 7, 2026, 08:11 PM
Package URL
pkg:socket/skills-sh/marioxe301%2Fsuper-worktree%2Fsuper-worktree%2F@202cf70913ffdfd13fccf7f2cde197e01aae0425