create-master

Warn

Audited by Socket on Apr 22, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
hooks/hooks.json

The hook mechanism is legitimate for extensibility but presents a non-trivial startup-time execution risk: if CLAUDE_PLUGIN_ROOT is tainted or if run-hook.cmd is malicious, arbitrary code could run at session start. Recommendations include restricting CLAUDE_PLUGIN_ROOT to trusted locations, implementing integrity verification (signatures, hashes) for run-hook.cmd, enabling least-privilege execution, adding auditing/logging of executed commands, and isolating the script execution (sandbox or container) where feasible.

Confidence: 59%Severity: 65%
AnomalyLOW
hooks/hooks-cursor.json

The code enables running an external local script at session start, which is a legitimate extensibility mechanism but introduces supply-chain and runtime risk. Without integrity verification, signing, or isolation, the script can become a backdoor or attack surface if tampered or replaced. Implement safeguards to mitigate risk in trusted environments.

Confidence: 59%Severity: 50%
Audit Metadata
Analyzed At
Apr 22, 2026, 03:42 AM
Package URL
pkg:socket/skills-sh/xr843%2FMaster-skill%2Fcreate-master%2F@b96d31881ee4ac74fa88d5dd93136036363d1513