git-worktree

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill is coherently aligned with its stated purpose of managing Git worktrees via a single manager script. It avoids unverified external downloads and keeps operations local to the developer's machine. The primary security considerations relate to the intentional copying of environment files (.env*) into new worktrees, which increases the potential exposure surface for secrets if worktrees are accessed in insecure contexts or shared systems. Overall, the footprint is benign and proportional to its purpose, with a moderate concern around handling of environment files that may contain sensitive data.

Confidence: 98%Severity: 25%
Audit Metadata
Analyzed At
Mar 10, 2026, 01:14 PM
Package URL
pkg:socket/skills-sh/udecode%2Fplate%2Fgit-worktree%2F@d0e94dde9b0237d6e4d5b642a92ea04e2103baed