Back to skill

Security audit

forktree

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward usage guide for a git worktree helper, with disclosed file-system effects and no hidden or automatic behavior in the artifact.

Install only if you intend to use the external `forktree` CLI for managing git worktrees. Review the CLI source or package provenance separately, and use dry-run or non-force modes before removing or garbage-collecting worktrees that may contain unmerged work.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

md
## Gotchas

- **Stdout is data, stderr is diagnostics.** `... | jq` is pipe-clean — but parse errors land on stderr, so for control flow check the exit code and read stderr on failure rather than relying on stdout content.
- **`forktree create` exit ≠ zero means no worktree.** Don't `cd "$wt"` without checking the exit; the variable is empty when the pre-flight refused.
- **`gc` is the cleanup path, not `remove`.** `gc` evaluates idle_days + merge status; `remove` deletes one worktree by path. Use `gc --dry-run` first when uncertain.
- **Setup hook (`[worktree].setup_script`) is opt-in and removes the worktree on non-zero exit.** Check the README before enabling — silent teardown on hook failure is by design.

Static analysis

No suspicious patterns detected.