engineering-skills

Warn

Audited by Socket on Mar 12, 2026

1 alert found:

Anomaly
AnomalyLOW
self-improving-agent/hooks/hooks.json

The configuration itself is small and not overtly malicious, but it instructs automatic execution of a package-supplied shell script (./hooks/error-capture.sh) which can perform any action available to the invoking user. This is a medium-to-high supply-chain risk until the referenced script is reviewed and its behavior validated. Treat the hook as potentially dangerous: do not allow it to run in sensitive environments without inspection or sandboxing.

Confidence: 75%Severity: 60%
Audit Metadata
Analyzed At
Mar 12, 2026, 05:31 PM
Package URL
pkg:socket/skills-sh/alirezarezvani%2Fclaude-skills%2Fengineering-skills%2F@e2bfc22ee8d5a4dee7654c90009439794be99478