codemod-react-pipeline
Warn
Audited by Socket on Jun 13, 2026
1 alert found:
AnomalyAnomalyhooks/hooks.json
LOWAnomalyLOW
hooks/hooks.json
This fragment does not show malicious behavior by itself, but it establishes an automatic shell-command execution point that runs a packaged script (`scripts/guardrail.sh`) derived from `${CLAUDE_PLUGIN_ROOT}`. Security depends entirely on the integrity of that script and the assurance that the plugin root cannot be tampered with; therefore, this should be treated as a meaningful supply-chain execution risk requiring inspection of guardrail.sh and verification of plugin root/path resolution.
Confidence: 100%Severity: 60%
Audit Metadata