scaffold-hooks
Warn
Audited by Socket on Sep 28, 2026
1 alert found:
AnomalyAnomalyharnesses/codex/scripts/test_skill.py
LOWAnomalyLOW
harnesses/codex/scripts/test_skill.py
No clear evidence of malware (no exfiltration, cryptomining, credential theft, or persistence) is present in this fragment. The primary security risk is that the code executes repository-derived shell/Python scripts and, critically, executes command strings from generated hooks.json using subprocess with shell=True and sources generated shell libraries via bash -c. If untrusted skill content is ever processed in a sensitive environment, this could enable arbitrary command execution. Treat this as a high-risk test harness pattern rather than proven sabotage.
Confidence: 59%Severity: 55%
Audit Metadata