dot-ai-worktree-prd

Warn

Audited by Socket on Mar 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill's functionality and requested actions are coherent with its stated purpose: creating a descriptive git worktree/branch from a PRD title. It requires local repository write access and the ability to run git commands; those capabilities are appropriate for the described task but are sensitive operations if performed autonomously by an agent. There are no signs of credential harvesting, remote exfiltration, or obfuscated/malicious code in the provided content. The main risks are operational: accidental branch/worktree collisions, unintended fetching of submodule remotes (which use existing credentials), and the danger of an agent executing these commands without explicit user confirmation. Mitigations: require explicit user approval before executing commands, validate/sanitize branch names thoroughly before invoking shell commands, and warn users about submodule network activity.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 2, 2026, 10:07 PM
Package URL
pkg:socket/skills-sh/vfarcic%2Fdot-ai%2Fdot-ai-worktree-prd%2F@41a56d529dac498d2f11a894797e3ae6dd634018