story-setup
Audited by Socket on Jul 26, 2026
2 alerts found:
Anomalyx2This module is a lifecycle hook runner that resolves a project root (from env/CWD), locates `.codex/hooks/run-story-hook.sh` (Unix) or `.codex/hooks/run-story-hook.cmd` (Windows), and executes it with the specified event. The snippet shows no explicit data theft or network activity, but it contains a high-impact arbitrary-code-execution pathway driven by repository-local hook content and uses `powershell -ExecutionPolicy Bypass` on Windows, increasing risk if the `.codex/hooks` files can be tampered with.
This file defines a local-bash hook execution framework that will run multiple scripts from a hidden project directory based on workflow events. The snippet itself shows no malicious payloads, credentials, or obfuscation, but it creates an explicit arbitrary command execution sink whose safety depends entirely on the integrity of "$CLAUDE_PROJECT_DIR" and the contents of "$CLAUDE_PROJECT_DIR/.claude/hooks/*.sh". Treat as potentially high workstation/supply-chain risk until those scripts are reviewed and integrity-verified.