self-improving-agent

Warn

Audited by Socket on Mar 11, 2026

1 alert found:

Anomaly
AnomalyLOW
hooks/hooks.json

The configuration itself is small and not overtly malicious, but it instructs automatic execution of a package-supplied shell script (./hooks/error-capture.sh) which can perform any action available to the invoking user. This is a medium-to-high supply-chain risk until the referenced script is reviewed and its behavior validated. Treat the hook as potentially dangerous: do not allow it to run in sensitive environments without inspection or sandboxing.

Confidence: 75%Severity: 60%
Audit Metadata
Analyzed At
Mar 11, 2026, 01:01 PM
Package URL
pkg:socket/skills-sh/alirezarezvani%2Fclaude-skills%2Fself-improving-agent%2F@fe7df97ceb835287a2c9d9f1766183a7c0beac40