setup-agent-skills

Warn

Audited by Socket on Aug 25, 2026

1 alert found:

Anomaly
AnomalyLOW
hook-templates/claude-settings.json

The provided code is not malicious by itself (no embedded payloads, secrets, or network actions are visible). However, it establishes a high-impact execution sink by running a local Node.js module on multiple lifecycle events, and it uses a runtime path variable to select the executed file. The actual malware/security risk cannot be confirmed without reviewing docs/agents/project-knowledge.mjs and how ${CLAUDE_PROJECT_DIR} is set and protected.

Confidence: 45%Severity: 60%
Audit Metadata
Analyzed At
Aug 25, 2026, 05:46 PM
Package URL
pkg:socket/skills-sh/zuozh11%2Fagent-skill-engineering%2Fsetup-agent-skills%2F@45208608c5c2e43d408444747e750cd6cc68cf6ac389996d4c6b47f2ada3ed36
Security Audit — socket — setup-agent-skills