cm

Warn

Audited by Socket on Jun 6, 2026

1 alert found:

Anomaly
AnomalyLOW
src/commands/guard.ts

The module is an installer that makes high-impact local changes by writing executable files and configuring both Claude Code and Git pre-commit hooks to execute a local guard script during developer workflows. The provided fragment itself shows no clear evidence of malware behaviors such as network exfiltration, credential theft, or obfuscated execution; however, the true malware/safety determination cannot be finalized without reviewing the payload constant (GIT_PRECOMMIT_HOOK) and the resulting Python script behavior, since that code will run at commit time. Treat as moderate security risk due to hook-based persistence and executable payload deployment, pending verification of the guard script contents.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 6, 2026, 04:03 AM
Package URL
pkg:socket/skills-sh/Dicklesworthstone%2Fcass_memory_system%2Fcm%2F@2e63e9ba81f155d48cfdc0f1d2c7d20a4996b3e9
Security Audit — socket — cm