trellis-meta

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Anomaly
AnomalyLOW
references/claude-code/hooks.md

No explicit malware is evidenced in the provided fragment alone, but the design creates meaningful security exposure: automated, configuration-driven local command execution (platform hooks + ralph-loop via worktree.yaml + task lifecycle sync) combined with dynamic inclusion of repository files into AI prompts via JSONL file lists. If an attacker can tamper with hook scripts or JSONL/worktree/config inputs, this could enable sabotage or sensitive data disclosure through LLM context. Review and harden the referenced hook script implementations and ensure strict validation/allowlisting for JSONL-listed paths and worktree.yaml/config.yaml commands.

Confidence: 42%Severity: 66%
Audit Metadata
Analyzed At
Apr 7, 2026, 05:34 AM
Package URL
pkg:socket/skills-sh/mindfold-ai%2Fmarketplace%2Ftrellis-meta%2F@7fe1b3cae81eff8a95570d1c4750a49e997d3382
Security Audit — socket — trellis-meta