harden-repo-for-coding-agents

Warn

Audited by Socket on Jun 18, 2026

1 alert found:

Anomaly
AnomalyLOW
templates/artifacts/gates/claude-settings.json

This settings fragment is primarily an execution-hook declaration. It will run a repository-local Python script from `.claude/hooks/` before any 'Bash' tool execution, creating a potentially serious supply-chain/workflow risk surface. The fragment contains no overt malicious logic, but because it deterministically enables execution of unseen repository code, the overall risk cannot be judged without reviewing the actual `.claude/hooks/<hook-filename>.py` contents and ensuring it is trustworthy and untampered.

Confidence: 60%Severity: 60%
Audit Metadata
Analyzed At
Jun 18, 2026, 09:39 PM
Package URL
pkg:socket/skills-sh/Thulr%2Fagent-skill-kit%2Fharden-repo-for-coding-agents%2F@4c0669b44069b0caa9446d796f0fffc09c750b5d9d8d93e95ee2e649421ec093
Security Audit — socket — harden-repo-for-coding-agents