pre-commit

Warn

Audited by Socket on May 17, 2026

1 alert found:

Anomaly
AnomalyLOW
Tools/package.json

The install script will execute local TypeScript code during installation (via bun run). That behavior is potentially dangerous because the executed code can perform arbitrary actions: modify git hooks, write/remove files, run network requests (telemetry/exfiltration), spawn shells, or otherwise harm the system. There are no obvious external HTTP fetches or non-registry dependency specifiers in this package.json, which reduces some supply-chain concerns, but you should inspect the PreCommitManager.ts (and any code it loads) before running npm/bun install. If you cannot review the code, treat this as untrusted and avoid running it as a privileged user.

Confidence: 80%Severity: 60%
Audit Metadata
Analyzed At
May 17, 2026, 02:58 AM
Package URL
pkg:socket/skills-sh/julianobarbosa%2Fclaude-code-skills%2Fpre-commit%2F@97ef1dafc64ec7e23ba1f340e34ed39d1ecf3d67
Security Audit — socket — pre-commit