claude-code-hooks

Warn

Audited by Socket on Mar 8, 2026

1 alert found:

Security
SecurityMEDIUM
references/configuration.md

This document describes a hook system that intentionally executes arbitrary command scripts in response to tool events. The fragment contains no hidden obfuscation or explicit malicious payload, but the mechanism itself is a high-value supply-chain risk: misconfiguration or compromise of the config files or hook scripts allows arbitrary code execution in developer/CI environments. Treat hook locations and scripts as sensitive: restrict write access, require code review, use signed or git-verified hooks, and prefer sandboxing or least-privilege execution. The code is not itself malware, but the configuration pattern enables powerful actions that can be abused.

Confidence: 80%Severity: 70%
Audit Metadata
Analyzed At
Mar 8, 2026, 04:40 PM
Package URL
pkg:socket/skills-sh/0xdarkmatter%2Fclaude-mods%2Fclaude-code-hooks%2F@c04381e63eb76f65e92e618ec95792bd6a6363b5