worktree-manager

Warn

Audited by Socket on Mar 14, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
scripts/launch-agent.sh

The script is a convenience launcher that itself contains no obvious backdoor or exfiltration code, but it executes an externally-configurable command (CLAUDE_CMD) without sanitization. If config.json or other inputs controlling CLAUDE_CMD are attacker-controlled, this leads to arbitrary command execution on the developer’s machine. Therefore the code is not directly malicious, but it creates a moderate-to-high risk execution sink and should be treated cautiously.

Confidence: 90%Severity: 60%
AnomalyLOW
SKILL.md

BENIGN with medium security risk. The skill’s capabilities largely match its stated worktree-management purpose, and installs/data flows are mostly local and official. The main concerns are the mandated use of `--dangerously-skip-permissions`, propagation of `.claude/` hooks/permissions, and copying env files into multiple worktrees, which broaden impact if an agent or hook misbehaves.

Confidence: 86%Severity: 64%
Audit Metadata
Analyzed At
Mar 14, 2026, 02:20 AM
Package URL
pkg:socket/skills-sh/scientiacapital%2Fskills%2Fworktree-manager%2F@61181504c03eefe9d7f14fb83baad85f8ca09390