greenfield

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/generate-settings.sh

This fragment does not contain explicit malware (no network/exfiltration, no secrets, no obfuscated payloads), but it creates high-privilege agent configuration that defers execution to multiple local bash hook scripts and writes broad command allow-lists based on PKG_MANAGER. The main risks are environment-controlled path trust (PROJECT_DIR, CLAUDE_PROJECT_DIR placeholder) and the power of the hook mechanism—if hook files or referenced directories are tampered with, the agent could execute arbitrary code in the project context.

Confidence: 60%Severity: 62%
Audit Metadata
Analyzed At
May 3, 2026, 05:16 PM
Package URL
pkg:socket/skills-sh/squirrelsoft-dev%2Fagent-skills%2Fgreenfield%2F@4c5b81c0b3b9d7176a953f3ae405e27e844afa73