enhance-hooks

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted hook files (.md, .sh, .json), creating a surface for external data to influence the agent's behavior.
  • Ingestion points: The skill reads hook files from a directory specified by the user via command-line arguments.
  • Boundary markers: There are no explicit instructions or delimiters defined to isolate the ingested code from the agent's internal analysis logic, which could be exploited if an LLM is used for evaluation.
  • Capability inventory: The skill workflow includes a "Fix" phase that writes automated improvements back to the files, providing a read-write capability on the file system.
  • Sanitization: While the skill detects safety violations in the target hooks, it does not specify sanitization for the content it reads before processing.
  • [SAFE]: The skill contains several high-risk command patterns (e.g., "rm -rf", "curl | sh", "eval", "git reset --hard") and destructive actions. These are documented strictly as detection signatures and "bad examples" for the auditing logic and are not executed by the skill itself.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 07:14 AM
Security Audit — agent-trust-hub — enhance-hooks