coding-standards

Warn

Audited by Socket on Jun 15, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS: The stated purpose and most capabilities are coherent for a coding-standards enforcement skill, and no credential theft or off-platform data routing is visible. The main concern is install/execution trust: bootstrap.py --auto-install changes persistent Claude hook configuration and may install packages from unspecified sources that cannot be verified from the provided content.

Confidence: 100%Severity: 60%
AnomalyLOW
hooks/settings.example.json

This snippet is not directly malicious; it is a pre-tool hook configuration that triggers automatic execution of multiple local Python scripts before write/edit/multiedit actions. The security risk is primarily indirect: it blindly runs code from a local path with no integrity checks, so tampering with the referenced `.claude/skills/coding-standards/hooks/` scripts could result in arbitrary code execution in the user’s environment.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 15, 2026, 01:40 AM
Package URL
pkg:socket/skills-sh/willey-labs%2Fagent-skills%2Fcoding-standards%2F@eaaf8df62089e7ee6c69f0eb9c3466e44180c1cf0a3a402aeb4593a461460d0e
Security Audit — socket — coding-standards