okf-wiki

Warn

Audited by Socket on Jul 26, 2026

1 alert found:

Anomaly
AnomalyLOW
example/.claude/settings.json

This snippet is a hook configuration that will execute two project-local Python scripts from a hidden directory during privileged lifecycle events (SessionStart and PreToolUse). No explicit malicious behavior is visible in the configuration itself, but it establishes a direct arbitrary code execution path whose real risk depends entirely on the contents and integrity of the referenced okf-anchor.py and okf-orient.py files. Review and verify the provenance/integrity of those scripts and ensure they are not replaceable by untrusted parties.

Confidence: 60%Severity: 62%
Audit Metadata
Analyzed At
Jul 26, 2026, 01:45 PM
Package URL
pkg:socket/skills-sh/jamditis%2Fclaude-skills-journalism%2Fokf-wiki%2F@a47f5abf990764ee2e76a06ad3c0e2437a962fc303480b2af7912f20b3ed58ff
Security Audit — socket — okf-wiki