writing-standards

Warn

Audited by Socket on Aug 13, 2026

1 alert found:

Anomaly
AnomalyLOW
hooks/settings.example.json

This snippet is not itself malicious code; it is a hook configuration that automatically executes a local Python script at session start and on every user prompt, and it explicitly states that the script’s stdout is added to the model context. That creates a significant trust and abuse surface: the referenced script’s provenance/integrity becomes the decisive factor for malware, privacy leakage, or prompt/context poisoning. Review and verify the exact inject-writing-standards.py content and its supply-chain integrity before use.

Confidence: 60%Severity: 55%
Audit Metadata
Analyzed At
Aug 13, 2026, 06:25 AM
Package URL
pkg:socket/skills-sh/willey-labs%2Fagent-skills%2Fwriting-standards%2F@236e2e61343fbd12188afa05cec70939b08cb226e4228568c011fd48d86f9e4e
Security Audit — socket — writing-standards