cc-hook-authoring
Warn
Audited by Socket on Aug 13, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s core behavior matches its purpose, and the examples are security-conscious, but it delegates installation of executable hook packs to unspecified MCP sources whose provenance cannot be verified from the skill text. No clear credential harvesting or malicious exfiltration is shown; risk is mainly from trust in fetched scripts plus the hooks’ ability to autonomously affect future agent actions.
Confidence: 84%Severity: 56%
Audit Metadata