create-hooks
Warn
Audited by Socket on Feb 17, 2026
1 alert found:
AnomalyAnomalyreferences/examples.md
LOWAnomalyLOW
references/examples.md
This report identifies a pragmatic, feature-rich hook framework with defensive checks and auditing. The primary risks arise from extensive local logging, potential command-execution pathways driven by config, and reliance on external safety scripts. While no malware or backdoors are evident, data exposure and supply-chain risk are non-trivial and should be mitigated through log redaction, restricted log access, stricter input sanitization, and formal data-handling policies. Recommend hardening the logging layer and ensuring only trusted hook configurations are deployed.
Confidence: 68%Severity: 60%
Audit Metadata