verify-worktree-plugins

Warn

Audited by Gen Agent Trust Hub on Mar 9, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script verify-worktree-plugins.sh performs multiple command-line operations including using grep to check files, sed and awk to modify content, and chmod +x to change file permissions on scripts within the ~/.claude directory. Additionally, the skill's instructions suggest implementing a TypeScript hook (context-compression-hook.ts) that uses execSync from node:child_process to run git commands during process compaction.\n- [PROMPT_INJECTION]: The skill is designed to inject instructions into the SKILL.md files of other plugins (specifically compound-engineering and superpowers). These patches use 'CRITICAL' and 'IMPORTANT' markers to provide directions that override or supplement the agent's behavior when using those plugins. This represents a capability for one skill to modify the instructional baseline of other agent skills.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 9, 2026, 02:12 PM