Hooks Automation

Fail

Audited by Socket on Apr 16, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The skill’s purpose broadly matches developer automation, but its footprint is high-risk because it turns many Claude Code events into automatic local shell execution and MCP actions. The main concern is not obvious malware or exfiltration, but broad autonomous hook execution with interpolated untrusted inputs and moderate installer trust ambiguity around the external CLI.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Apr 16, 2026, 08:53 AM
Package URL
pkg:socket/skills-sh/ruvnet%2Fclaude-flow%2Fhooks-automation%2F@ea7ecdf9b99acea8ff50d852d555dd3c09cd7171