boss

Warn

Audited by Socket on May 13, 2026

1 alert found:

Anomaly
AnomalyLOW
hooks/hooks.json

No explicit malware indicators (secrets, obfuscation, suspicious network destinations) are present in this configuration fragment. However, it establishes a high-impact execution pathway by dynamically running local JavaScript hook scripts via a command runner at sensitive pipeline lifecycle events. Security therefore hinges on the integrity and correctness of `scripts/hooks/*.js` and the `boss` hook runner; review and verify those implementations and their supply-chain integrity to rule out exfiltration or tampering. Overall: likely guardrail orchestration, with structural supply-chain risk due to delegated script execution.

Confidence: 55%Severity: 60%
Audit Metadata
Analyzed At
May 13, 2026, 11:10 AM
Package URL
pkg:socket/skills-sh/echoVic%2Fboss-skill%2Fboss%2F@2610d91ffcf54da35110e8373f11dc4bf557ed64