environments-manager
Warn
Audited by Socket on Aug 7, 2026
1 alert found:
AnomalyAnomalyexamples/claude/settings.json
LOWAnomalyLOW
examples/claude/settings.json
This snippet itself is not evidence of malicious code, but it is a high-impact delegation mechanism: it configures automatic execution of two external shell scripts on worktree create/remove. The security posture depends on the trustworthiness and integrity of "$CLAUDE_PROJECT_DIR/scripts/claude-worktree-*.sh" and on whether "$CLAUDE_PROJECT_DIR" is protected from attacker influence. Review and lock down the script contents and the environment variable setting before deploying this hook configuration.
Confidence: 55%Severity: 52%
Audit Metadata