harness-engineering

Warn

Audited by Socket on Apr 20, 2026

1 alert found:

Anomaly
AnomalyLOW
templates/settings.json

This fragment is a hook/permission configuration that executes three local Python scripts on sensitive lifecycle events (including user prompt submission) and grants a broad shell/tool execution surface (notably npm/npx/node/git plus filesystem operations). The snippet itself shows no explicit credentials, network, or exfiltration; however, it creates a high-impact control-plane path where any malicious or compromised code inside .claude/hooks/*.py (especially the context-injector) could tamper with agent behavior and potentially trigger harmful actions through the allowed command surface. Inspect and validate the actual hook script contents and the workflow’s data-access/network constraints.

Confidence: 60%Severity: 60%
Audit Metadata
Analyzed At
Apr 20, 2026, 02:44 AM
Package URL
pkg:socket/skills-sh/kangarooking%2Fkangarooking-skills%2Fharness-engineering%2F@5d4f078e2d9f25d50d88f55d5dfee7c1f4a21e04