trellis-meta
Warn
Audited by Socket on Sep 17, 2026
1 alert found:
AnomalyAnomalyreferences/claude-code/multi-session.md
LOWAnomalyLOW
references/claude-code/multi-session.md
This fragment is documentation for an automation framework rather than malicious payload code. No direct malware, credential exfiltration, reverse shell, cryptomining, or suspicious network destination is shown. It does describe high-impact automation: arbitrary hook execution, environment-file copying, privileged agent execution, dependency installation, Git pushes, and GitHub PR creation. These behaviors present meaningful security and supply-chain risk if configuration, tasks, dependencies, or agent prompts are compromised, but the fragment alone does not establish malicious intent.
Confidence: 93%Severity: 62%
Audit Metadata