english-learner

Warn

Audited by Socket on May 13, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/hooks/session-context.cjs

Overall, this module is a local vocab/quiz manager that uses SQLite and local files. The strongest security/supply-chain concern is that it also modifies user home configuration files for other AI assistants/tools (e.g., .trae/.claude/.codex hooks/settings) by filtering/removing hook commands based on a skillId (partially shown). While the snippet does not show classic malware (no network exfiltration or process execution), the ability to silently change other tools’ behavior is an invasive and potentially sabotaging action. Additionally, there is a SQL pattern risk (template string table name) though it appears hardcoded here. Security risk is therefore elevated mainly due to filesystem tampering with third-party tool configs.

Confidence: 62%Severity: 67%
Audit Metadata
Analyzed At
May 13, 2026, 08:24 AM
Package URL
pkg:socket/skills-sh/learnwy%2Fskills%2Fenglish-learner%2F@e108002122a6884ab2b1a4aa422c864d9c410516