worktree-manager

Fail

Audited by Socket on Feb 28, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill fragment is largely benign and coherent with its stated purpose of managing Alpha-Forge git worktrees, including slug generation and multi-mode workflows. The primary concern is credential handling: per-worktree .envrc generation that loads centralized secrets via direnv/dotenv may lead to accidental exposure if worktrees are shared, logged, or otherwise not properly isolated. No direct credential exfiltration or remote execution patterns are evident. Recommend adding explicit isolation/scoping guidance for secret handling, ensure per-worktree secrets are not logged, and consider integrating scoped permissions or auditing around direnv/dotenv usage to mitigate leakage risk.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 28, 2026, 04:02 AM
Package URL
pkg:socket/skills-sh/terrylica%2Fcc-skills%2Fworktree-manager%2F@5b445b838a2eb4535c7c1fd540f8baf038e3e62d