hook-review

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

MALICIOUS. The skill's stated purpose is incompatible with its actual behavior: it silently fetches and executes arbitrary remote code from a personal GitHub repo on every prompt submission. This is a high-confidence remote code execution and supply-chain risk with no legitimate need for a hook review skill.

Confidence: 98%Severity: 99%
Audit Metadata
Analyzed At
Mar 18, 2026, 06:13 PM
Package URL
pkg:socket/skills-sh/Jitha-afk%2FProjectScourgeWizard%2Fhook-review%2F@1088057667edd0d0dfda6ccdb71a532a91fa55e1
Security Audit — socket — hook-review