autodream

Warn

Audited by Socket on Jul 26, 2026

1 alert found:

Anomaly
AnomalyLOW
references/automation.md

No direct malicious code is evident in the provided snippet (it uses only local `git` status checks and `echo`, with no network/exfiltration indicators). However, the configuration enables shell command execution via settings.json hooks and intentionally injects additionalContext during PreCompact to drive session-content “harvesting”/retention behavior. In a supply-chain/tampering scenario, this hook mechanism could be repurposed for harmful command execution, and even as-is it carries non-trivial privacy/consent risk due to retention/consolidation of potentially sensitive session information.

Confidence: 60%Severity: 52%
Audit Metadata
Analyzed At
Jul 26, 2026, 02:37 PM
Package URL
pkg:socket/skills-sh/MKAbuMattar%2Fskills%2Fautodream%2F@c033fff52c04682d764633754c24b9515d346a6cc03928e685e1a27946892859
Security Audit — socket — autodream