hook-creator

Fail

Audited by Socket on Mar 5, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
references/official-hooks-docs.md

The documentation defines a powerful hook system that intentionally permits arbitrary shell execution and transmission of hook context to external LLMs. The documentation itself is benign, but the mechanisms it defines enable high-impact abuses (data exfiltration, credential theft, filesystem destruction, covert persistence) if hook configurations or plugin hooks are malicious or misconfigured. Operators must treat hook configurations and plugin-provided hooks as high-risk supply-chain components and apply strict review, isolation, and least-privilege controls before enabling them.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 5, 2026, 08:20 AM
Package URL
pkg:socket/skills-sh/VitaDynamics%2Fvita-cc-market%2Fhook-creator%2F@ded524ea9e01fab603e934b2d7984daa9de425ee