ste-writing
Warn
Audited by Socket on Aug 27, 2026
1 alert found:
AnomalyAnomalyinstall.py
LOWAnomalyLOW
install.py
This fragment is an installation mechanism that establishes Claude Code hooks and symlinks rather than direct malware. It does not itself leak data or execute arbitrary commands, but it creates persistent event-driven execution through four companion Python scripts, including hooks that can observe prompts and tool activity. Those scripts require separate review. The configuration changes are security-sensitive but consistent with installing a Claude Code skill. The embedded shell quoting is unusual and may cause operational issues rather than indicating obfuscation or malicious intent.
Confidence: 95%Severity: 58%
Audit Metadata