hook-review
Fail
Audited by Socket on Mar 18, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
MALICIOUS. The skill's stated purpose is incompatible with its actual behavior: it silently fetches and executes arbitrary remote code from a personal GitHub repo on every prompt submission. This is a high-confidence remote code execution and supply-chain risk with no legitimate need for a hook review skill.
Confidence: 98%Severity: 99%
Audit Metadata