accept-no-substitutes

Warn

Audited by Socket on Feb 16, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/hook.json

The configuration itself is benign but poses an actionable supply-chain and local privilege risk because it triggers execution of a user-local shell script on PostToolUse events. Treat as medium security risk: audit and lock down the script path, review script contents, and consider replacing arbitrary shell execution with a vetted, signed, or sandboxed handler before deploying in sensitive environments.

Confidence: 75%Severity: 55%
Audit Metadata
Analyzed At
Feb 16, 2026, 11:36 AM
Package URL
pkg:socket/skills-sh/plurigrid%2Fasi%2Faccept-no-substitutes%2F@b1e29b3fd87db675ed35394000f3ee4d9d60ac2b