ste-writing

Warn

Audited by Socket on Aug 27, 2026

1 alert found:

Anomaly
AnomalyLOW
install.py

This fragment is an installation mechanism that establishes Claude Code hooks and symlinks rather than direct malware. It does not itself leak data or execute arbitrary commands, but it creates persistent event-driven execution through four companion Python scripts, including hooks that can observe prompts and tool activity. Those scripts require separate review. The configuration changes are security-sensitive but consistent with installing a Claude Code skill. The embedded shell quoting is unusual and may cause operational issues rather than indicating obfuscation or malicious intent.

Confidence: 95%Severity: 58%
Audit Metadata
Analyzed At
Aug 27, 2026, 01:40 PM
Package URL
pkg:socket/skills-sh/woosal1337%2Fblog%2Fste-writing%2F@a4d08c2921651ef3aa89e5ef4a7cf8c7ea3d45805049cac02d496e9c4e528dd4
Security Audit — socket — ste-writing