beam

Warn

Audited by Socket on Aug 18, 2026

1 alert found:

Anomaly
AnomalyLOW
references/claude-code-hooks.json

No direct indicators of malware or obfuscation are present in this fragment alone; it contains a straightforward hook configuration. The main security concern is that it performs lifecycle-triggered command execution of a specific Node.js script via an absolute path and passes an environment-derived endpoint without visible validation, leaving the actual risk largely dependent on the behavior of the referenced `beam` script and how $BEAM_ENDPOINT is set/validated elsewhere. The safest assessment is a moderate supply-chain/runtime risk requiring review of the invoked script and endpoint handling.

Confidence: 46%Severity: 50%
Audit Metadata
Analyzed At
Aug 18, 2026, 07:49 PM
Package URL
pkg:socket/skills-sh/openclaw%2Fagent-skills%2Fbeam%2F@6e0ff8e769aea96275771d5ad8d5697fa29d1114e977f0c35c81c807529ccee6
Security Audit — socket — beam