agent-readiness

Warn

Audited by Socket on Jun 15, 2026

1 alert found:

Anomaly
AnomalyLOW
templates/artifacts/gates/claude-settings.json

This settings fragment is primarily an execution-hook declaration. It will run a repository-local Python script from `.claude/hooks/` before any 'Bash' tool execution, creating a potentially serious supply-chain/workflow risk surface. The fragment contains no overt malicious logic, but because it deterministically enables execution of unseen repository code, the overall risk cannot be judged without reviewing the actual `.claude/hooks/<hook-filename>.py` contents and ensuring it is trustworthy and untampered.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 15, 2026, 02:34 PM
Package URL
pkg:socket/skills-sh/Thulr%2Finformed-skills%2Fagent-readiness%2F@e517b435a01cab62edcdc78ed5a0dc8b50467dbcaf2f6d75b2a6da94d0f4bdab
Security Audit — socket — agent-readiness