worktree

Fail

Audited by Socket on Mar 22, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The skill’s purpose is coherent for repository worktree management, and most git-related actions are proportionate. However, its core dependency is an unverifiable `noodle` CLI with broad execution and install side effects, so trust in installation and execution is not established; this drives high security risk even without evidence of confirmed malware or external credential exfiltration.

Confidence: 82%Severity: 82%
Audit Metadata
Analyzed At
Mar 22, 2026, 01:17 AM
Package URL
pkg:socket/skills-sh/poteto%2Fnoodle%2Fworktree%2F@4af53b81527d61fc3e0c300c49cf013e2ce973a8