project-agentification

Warn

Audited by Socket on May 18, 2026

1 alert found:

Anomaly
AnomalyLOW
templates/artifacts/gates/claude-settings.json

This settings fragment is primarily an execution-hook declaration. It will run a repository-local Python script from `.claude/hooks/` before any 'Bash' tool execution, creating a potentially serious supply-chain/workflow risk surface. The fragment contains no overt malicious logic, but because it deterministically enables execution of unseen repository code, the overall risk cannot be judged without reviewing the actual `.claude/hooks/<hook-filename>.py` contents and ensuring it is trustworthy and untampered.

Confidence: 60%Severity: 60%
Audit Metadata
Analyzed At
May 18, 2026, 09:47 PM
Package URL
pkg:socket/skills-sh/Thulr%2Finformed-skills%2Fproject-agentification%2F@0755ccecaa76a9a289e0d08e85ab2a10f20d6670
Security Audit — socket — project-agentification