harness
Warn
Audited by Socket on Sep 23, 2026
1 alert found:
AnomalyAnomalyhooks/self-reflect-stop.py
LOWAnomalyLOW
hooks/self-reflect-stop.py
The code appears to implement a project-specific reflection hook and shows no clear malware behavior. However, the unvalidated session_id controls a file path used for reads and writes, creating a potentially serious path-traversal vulnerability. Validate or strictly constrain session_id and use safe, private counter-file handling.
Confidence: 96%Severity: 63%
Audit Metadata