laws-of-software-los

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
assets/codex-hooks/hooks.global.json

No explicit malicious payloads, credential theft, network exfiltration, or obfuscation are visible in this configuration alone. However, it repeatedly executes Python code from a user-writable directory ($HOME/.codex/hooks/...) at multiple sensitive lifecycle stages, without any shown integrity verification. This creates a meaningful supply-chain/local-tampering risk: if those scripts are altered, arbitrary code execution could occur reliably. The referenced Python files should be reviewed and protected with integrity controls (hash/signature verification, permissions/ownership enforcement, and immutability or least-privilege execution).

Confidence: 62%Severity: 62%
Audit Metadata
Analyzed At
Apr 21, 2026, 08:12 PM
Package URL
pkg:socket/skills-sh/MylesMCook%2Fmcook-skills%2Flaws-of-software-los%2F@0be71ea105f161a23ecf8e1bd972e6fc4f3c323f