beam
Warn
Audited by Socket on Aug 18, 2026
1 alert found:
AnomalyAnomalyreferences/claude-code-hooks.json
LOWAnomalyLOW
references/claude-code-hooks.json
No direct indicators of malware or obfuscation are present in this fragment alone; it contains a straightforward hook configuration. The main security concern is that it performs lifecycle-triggered command execution of a specific Node.js script via an absolute path and passes an environment-derived endpoint without visible validation, leaving the actual risk largely dependent on the behavior of the referenced `beam` script and how $BEAM_ENDPOINT is set/validated elsewhere. The safest assessment is a moderate supply-chain/runtime risk requiring review of the invoked script and endpoint handling.
Confidence: 46%Severity: 50%
Audit Metadata