scaffold-hooks

Warn

Audited by Socket on Sep 28, 2026

1 alert found:

Anomaly
AnomalyLOW
harnesses/codex/scripts/test_skill.py

No clear evidence of malware (no exfiltration, cryptomining, credential theft, or persistence) is present in this fragment. The primary security risk is that the code executes repository-derived shell/Python scripts and, critically, executes command strings from generated hooks.json using subprocess with shell=True and sources generated shell libraries via bash -c. If untrusted skill content is ever processed in a sensitive environment, this could enable arbitrary command execution. Treat this as a high-risk test harness pattern rather than proven sabotage.

Confidence: 59%Severity: 55%
Audit Metadata
Analyzed At
Sep 28, 2026, 12:40 AM
Package URL
pkg:socket/skills-sh/jpcaparas%2Fskills%2Fscaffold-hooks%2F@4691debdf1a5020332690130fab583b864c7642108868981e1d630487441dd66
Security Audit — socket — scaffold-hooks