popcorn-xp

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Anomaly
AnomalyLOW
hooks/hooks.json

This is an execution-based lifecycle hook configuration that runs three bash scripts from `${CLAUDE_PLUGIN_ROOT}/hooks/scripts/` on common lifecycle events. No direct malicious indicators appear in the fragment, but it creates a strong supply-chain risk point: if `${CLAUDE_PLUGIN_ROOT}` is manipulable or the referenced scripts are tampered with, arbitrary code execution could occur. Review and integrity-verify the referenced shell scripts and the mechanism that sets/controls `${CLAUDE_PLUGIN_ROOT}`.

Confidence: 52%Severity: 55%
Audit Metadata
Analyzed At
Apr 1, 2026, 05:38 PM
Package URL
pkg:socket/skills-sh/mikewolfd%2Fxp-popcorn-skill%2Fpopcorn-xp%2F@5c51ab9a2a3cab8f9100fa78789bbce1c8b42d36