hook-factory
Audited by Socket on Sep 22, 2026
2 alerts found:
Anomalyx2No direct malware behavior (network exfiltration, credential theft, subprocess execution, or obfuscation) is visible in this module. However, it is a high-impact hook-generation and persistence tool: it accepts a free-form user command, relies on delegated/unknown generator+validator+installer logic, and only warns (does not block) when HookValidator deems content unsafe. As a result, the overall supply-chain/security risk is medium to high, primarily due to the likelihood of producing and possibly auto-installing hook definitions that could execute harmful commands later by downstream components.
No direct malware behavior (no exfiltration, reverse shells, or destructive actions) is evident in the provided fragment. However, it persistently logs arbitrary user prompts from an environment variable to disk and can print local context file contents to stdout, both without redaction—creating a meaningful privacy/sensitive-data retention risk that is suspicious in a supply-chain context.