enhance-hooks
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted hook files (.md, .sh, .json), creating a surface for external data to influence the agent's behavior.
- Ingestion points: The skill reads hook files from a directory specified by the user via command-line arguments.
- Boundary markers: There are no explicit instructions or delimiters defined to isolate the ingested code from the agent's internal analysis logic, which could be exploited if an LLM is used for evaluation.
- Capability inventory: The skill workflow includes a "Fix" phase that writes automated improvements back to the files, providing a read-write capability on the file system.
- Sanitization: While the skill detects safety violations in the target hooks, it does not specify sanitization for the content it reads before processing.
- [SAFE]: The skill contains several high-risk command patterns (e.g., "rm -rf", "curl | sh", "eval", "git reset --hard") and destructive actions. These are documented strictly as detection signatures and "bad examples" for the auditing logic and are not executed by the skill itself.
Audit Metadata