hooks-builder

Fail

Audited by Socket on Feb 19, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
references/schema.md

This document is a schema and usage guide for a hook system that can alter agent behavior and execute host commands. The text itself is not executable malicious code, but it specifies features (arbitrary command execution, silent permission grants, system-level context injection, suppression of output) that are high-risk if implementations accept untrusted configuration or inputs. No direct signs of malware, obfuscation, or hard-coded secrets are present in the specification; however, deployments of this system require strict access control, input validation, sandboxing of command hooks, and audit/logging to prevent RCE, permission bypass, data leakage, or denial-of-service.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 19, 2026, 11:30 AM
Package URL
pkg:socket/skills-sh/bsamiee%2Fparametric_forge%2Fhooks-builder%2F@754c6caf321eb437949b53845281105812357778