hook-creator

Fail

Audited by Socket on Mar 5, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The code/documentation itself is legitimate guidance for a hook system but documents high-risk capabilities: arbitrary shell execution, runtime downloads (npx), persistent logging, and agent-control via exit codes. These are normal for such a system but materially increase supply-chain and local-risk if hook configs or the loader are compromised. Recommend restricting write access to hook config files, requiring signing or explicit user approval for new/changed hooks, avoiding unpinned runtime package downloads (pin versions or vendoring), sandboxing hook execution, and limiting network access from hooks.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 5, 2026, 06:56 AM
Package URL
pkg:socket/skills-sh/evanfang0054%2Fcc-system-creator-scripts%2Fhook-creator%2F@b2e6b7cfe10888577b7aaf7d53e3359df7ad3797