meta-hook-creator

Warn

Audited by Socket on Feb 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This is a documentation/template skill describing how to create lifecycle hooks for Claude Code. The content itself contains no explicit malicious code, hard-coded credentials, obfuscated payloads, or download-and-execute instructions. However, the documented capabilities (arbitrary shell commands, subagents, writing CLAUDE_ENV_FILE, and async/background execution) are powerful and, if misused or if untrusted hooks are installed, could enable credential harvesting, data exfiltration, command injection, or autonomous actions. Risk therefore arises from hook implementations and deployment policies rather than from this document alone. Recommend: enforce code review, require least privilege for hooks, restrict network access or whitelisted endpoints for hook processes, and avoid installing untrusted hook scripts.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 24, 2026, 08:38 PM
Package URL
pkg:socket/skills-sh/oakoss%2Fagent-skills%2Fmeta-hook-creator%2F@e194860adac04d0102427872e26e1d7639ef8062