using-agent-skills

Warn

Audited by Socket on Sep 8, 2026

1 alert found:

Anomaly
AnomalyLOW
upstream-bundle/hooks/hooks.json

This snippet implements an extensibility mechanism that performs arbitrary shell code execution at SessionStart by running a local session-start.sh file whose location is derived from environment variables and selected based on filesystem existence. While the fragment itself contains no explicit malicious payloads, the absence of provenance/integrity validation and the fallback to a hidden project-local directory create a meaningful supply-chain/persistence risk if those directories or files can be modified by an attacker. The referenced session-start.sh scripts should be reviewed and their provenance/permissions verified.

Confidence: 62%Severity: 67%
Audit Metadata
Analyzed At
Sep 8, 2026, 06:56 AM
Package URL
pkg:socket/skills-sh/seaworld008%2Fcommonly-used-high-value-skills%2Fusing-agent-skills%2F@0e1f79b2472b73caaf38935c1a2225cc6b8a8d93ed008187d300f38ccf0e1c9a
Security Audit — socket — using-agent-skills