worktree-setup
Warn
Audited by Socket on Mar 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill is broadly aligned with worktree setup, but its preferred path depends on an unrelated third-party global CLI installed unpinned from npm, and it copies secret-bearing `.env` files while also allowing project-defined post-create commands to run. No clear exfiltration or overtly malicious behavior is shown, but the install trust and local-impact footprint are higher than ideal for a setup helper.
Confidence: 87%Severity: 58%
Audit Metadata