autodream
Warn
Audited by Socket on Jul 26, 2026
1 alert found:
AnomalyAnomalyreferences/automation.md
LOWAnomalyLOW
references/automation.md
No direct malicious code is evident in the provided snippet (it uses only local `git` status checks and `echo`, with no network/exfiltration indicators). However, the configuration enables shell command execution via settings.json hooks and intentionally injects additionalContext during PreCompact to drive session-content “harvesting”/retention behavior. In a supply-chain/tampering scenario, this hook mechanism could be repurposed for harmful command execution, and even as-is it carries non-trivial privacy/consent risk due to retention/consolidation of potentially sensitive session information.
Confidence: 60%Severity: 52%
Audit Metadata