Worktrunk

PassAudited by VirusTotal on May 2, 2026.

Findings (1)

The skill bundle describes a Git worktree management tool that includes high-risk capabilities, specifically arbitrary command execution via the `-x` flag and automated shell hooks defined in `.worktrunk/hooks.toml`. While these features are aligned with the stated purpose of automating parallel development workflows, they provide a direct path for command injection or unauthorized execution if the agent processes untrusted input. No evidence of intentional malice, such as data exfiltration or backdoors, was found in SKILL.md or _meta.json.