hooks-development
Warn
Audited by Socket on Sep 26, 2026
2 alerts found:
Anomalyx2Anomalyreferences/hook-templates.md
LOWAnomalyLOW
references/hook-templates.md
The excerpt appears to be hook documentation or template material, not clear evidence of malware. Its example path-expansion line is unsafe: if used with attacker-controlled file paths, `eval` can enable shell command injection. Whether that risk applies to the containing project depends on how this template is incorporated and invoked.
Confidence: 97%Severity: 56%
Anomalyreferences/visibility-patterns.md
LOWAnomalyLOW
references/visibility-patterns.md
The document is not itself malware. Its embedded Bash example contains a command-injection vulnerability because it applies `eval` to a path derived from hook input. Use a non-evaluating path-expansion approach and validate the input instead.
Confidence: 98%Severity: 62%
Audit Metadata