agentsclimarketplace

Safe worktree slug validation

Skill vishuwa2004/cskill-agents/agents/codex/skills/safe-worktree-slug-validation

Build curated agent skills for coding CLIs, terminal tools, context engines, remote bridges, and multi-agent runtimes

Install
npx -y skills add vishuwa2004/cskill-agents --skill safe-worktree-slug-validation

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 2 stars2 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Ensure Git worktree slugs can never escape the managed workspace or inject traversal.

SKILL.md

1.9 KB, 380 tokens by cl100k_base, as published. Nobody here has run it

SKILL: Safe Worktree Slug Validation

Domain: git-worktree Trigger: Apply this when accepting user-provided prefixes for enter worktree and you need to guarantee no path traversal or invalid chars slip into the worktree directory. Source Pattern: Distilled from reviewed permission, shell-safety, and worktree-management implementations.

Core Method

Split a slug on /, reject segments that are empty, . or .., or contain characters outside a za z0 9, and enforce a maximum combined length before joining the cleaned segments into a deterministic branch name and path. Perform this validation synchronously before invoking any git commands so the CLI never creates directories outside claude worktrees.

Key Rules

  • Validate each /-separated segment independently so user evil and similar mashups fail early.
  • Enforce a total length cap (e.g., 64 chars) before git worktree add to prevent excessively long refs or paths.
  • Reject slugs with leading/trailing slashes or repeated .. segments even when a normalization would neutralize them.
  • Run this check before any git fetch, mkdir, or hook execution to avoid partial side effects.

Example Application

Any agent producing a worktree name for a release hotfix can reuse this skill: call the validator on the proposed slug, surface a concise error message if it fails, and refuse to call git worktree add until the slug is safe.

Anti-Patterns (What NOT to do)

  • Do not rely on git worktree add to detect traversal; it may silently create directories in unexpected locations.
  • Do not treat slugs as a single string (e.g., foo bar) without splitting, because multi-segment checks are necessary.
  • Avoid waiting until after mkdir or config changes—the validation must run before any side effects.

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.