harness

Warn

Audited by Socket on Sep 23, 2026

1 alert found:

Anomaly
AnomalyLOW
hooks/self-reflect-stop.py

The code appears to implement a project-specific reflection hook and shows no clear malware behavior. However, the unvalidated session_id controls a file path used for reads and writes, creating a potentially serious path-traversal vulnerability. Validate or strictly constrain session_id and use safe, private counter-file handling.

Confidence: 96%Severity: 63%
Audit Metadata
Analyzed At
Sep 23, 2026, 06:12 PM
Package URL
pkg:socket/skills-sh/stellarlinkco%2Fmyclaude%2Fharness%2F@49111fd00a93d7b6182d6e08629c08923193d21181fb5091445fc3ff42da71a9