claude-reflect

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
install-hooks.sh

This installer adds local hooks that log nearly all tool activity (commands, file paths, timestamps) and stores these records unencrypted under workspace-hub/.claude/state (or $HOME/.claude). There is no network exfiltration or obfuscated payload in the provided code, so it does not appear to be malware in the traditional sense. However, it is privacy-invasive telemetry and a supply-chain risk: installing it into a repository will start collecting potentially sensitive developer activity and repository context. Treat this as a privacy/security concern: require explicit user consent, audit the stored logs, restrict file permissions, and review any automated uploads or subsequent tools that might read and transmit these logs.

Confidence: 90%Severity: 60%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:16 PM
Package URL
pkg:socket/skills-sh/vamseeachanta%2Fworkspace-hub%2Fclaude-reflect%2F@ae0402f45e9817d928a3e708a78ab68be9678056