codemod-react-pipeline

Warn

Audited by Socket on Jun 13, 2026

1 alert found:

Anomaly
AnomalyLOW
hooks/hooks.json

This fragment does not show malicious behavior by itself, but it establishes an automatic shell-command execution point that runs a packaged script (`scripts/guardrail.sh`) derived from `${CLAUDE_PLUGIN_ROOT}`. Security depends entirely on the integrity of that script and the assurance that the plugin root cannot be tampered with; therefore, this should be treated as a meaningful supply-chain execution risk requiring inspection of guardrail.sh and verification of plugin root/path resolution.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 13, 2026, 03:54 AM
Package URL
pkg:socket/skills-sh/pproenca%2Fdot-skills%2Fcodemod-react-pipeline%2F@11f56e29f785d65d800b31553a0a10de986ad95e69a179a52eaca2e58f81534b
Security Audit — socket — codemod-react-pipeline