story-setup
Audited by Socket on Aug 26, 2026
2 alerts found:
Anomalyx2This module is a lifecycle hook runner that resolves a project root (from env/CWD), locates `.codex/hooks/run-story-hook.sh` (Unix) or `.codex/hooks/run-story-hook.cmd` (Windows), and executes it with the specified event. The snippet shows no explicit data theft or network activity, but it contains a high-impact arbitrary-code-execution pathway driven by repository-local hook content and uses `powershell -ExecutionPolicy Bypass` on Windows, increasing risk if the `.codex/hooks` files can be tampered with.
This fragment is not itself malicious code, but it is a powerful hook dispatcher that repeatedly executes multiple local bash scripts from a hidden project directory (".claude/hooks") based on workflow events. The security risk is primarily contingent on the integrity and provenance of the referenced scripts and the runtime value of "$CLAUDE_PROJECT_DIR". Inspect and verify all .claude/hooks/*.sh contents (and ensure $CLAUDE_PROJECT_DIR cannot be influenced by an attacker).