okf-wiki
Warn
Audited by Socket on Jul 26, 2026
1 alert found:
AnomalyAnomalyexample/.claude/settings.json
LOWAnomalyLOW
example/.claude/settings.json
This snippet is a hook configuration that will execute two project-local Python scripts from a hidden directory during privileged lifecycle events (SessionStart and PreToolUse). No explicit malicious behavior is visible in the configuration itself, but it establishes a direct arbitrary code execution path whose real risk depends entirely on the contents and integrity of the referenced okf-anchor.py and okf-orient.py files. Review and verify the provenance/integrity of those scripts and ensure they are not replaceable by untrusted parties.
Confidence: 60%Severity: 62%
Audit Metadata