daily-report
Warn
Audited by Socket on May 18, 2026
1 alert found:
AnomalyAnomaly.claude/settings.local.json
LOWAnomalyLOW
.claude/settings.local.json
No explicit malicious payloads are shown in this permissions snippet, but it substantially expands the agent’s ability to fetch remote, instruction-like content and to execute command/npm tooling based on external inputs. The broad curl/API capabilities (curl * and gh api *), combined with npx execution and lack of evident integrity pinning, make this a moderate-to-high supply-chain risk that warrants review of the orchestrator and any downloaded/executed artifacts for integrity and safety constraints.
Confidence: 66%Severity: 68%
Audit Metadata