worktree-manager

Warn

Audited by Socket on Mar 27, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
scripts/launch-agent.sh

The script is a convenience launcher that itself contains no obvious backdoor or exfiltration code, but it executes an externally-configurable command (CLAUDE_CMD) without sanitization. If config.json or other inputs controlling CLAUDE_CMD are attacker-controlled, this leads to arbitrary command execution on the developer’s machine. Therefore the code is not directly malicious, but it creates a moderate-to-high risk execution sink and should be treated cautiously.

Confidence: 90%Severity: 60%
AnomalyLOW
SKILL.md

BENIGN with medium security risk. The skill’s capabilities largely match its stated worktree-management purpose, and installs/data flows are mostly local and official. The main concerns are the mandated use of `--dangerously-skip-permissions`, propagation of `.claude/` hooks/permissions, and copying env files into multiple worktrees, which broaden impact if an agent or hook misbehaves.

Confidence: 86%Severity: 64%
Audit Metadata
Analyzed At
Mar 27, 2026, 08:01 PM
Package URL
pkg:socket/skills-sh/scientiacapital%2Fskills%2Fworktree-manager%2F@b576e4a64dd9a3d167ab0c5bd7606a25a92e0936