Plugin Structure
Warn
Audited by Socket on Aug 6, 2026
1 alert found:
AnomalyAnomalyexamples/advanced-plugin.md
LOWAnomalyLOW
examples/advanced-plugin.md
No explicit malicious logic or obfuscation is visible in the provided fragment; most content is operational guidance. The primary security finding is that the hook configuration defines repeated execution of multiple local bash scripts and includes cluster/log operations via MCP. Because the contents of the referenced scripts and MCP servers are not included, malware cannot be confirmed, but the automation hook execution surface is high impact and should be treated as a critical trust boundary (verify script integrity, permissions, and any log handling).
Confidence: 46%Severity: 62%
Audit Metadata