agent-readiness
Warn
Audited by Socket on Jun 15, 2026
1 alert found:
AnomalyAnomalytemplates/artifacts/gates/claude-settings.json
LOWAnomalyLOW
templates/artifacts/gates/claude-settings.json
This settings fragment is primarily an execution-hook declaration. It will run a repository-local Python script from `.claude/hooks/` before any 'Bash' tool execution, creating a potentially serious supply-chain/workflow risk surface. The fragment contains no overt malicious logic, but because it deterministically enables execution of unseen repository code, the overall risk cannot be judged without reviewing the actual `.claude/hooks/<hook-filename>.py` contents and ensuring it is trustworthy and untampered.
Confidence: 100%Severity: 60%
Audit Metadata