hook-factory
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEPERSISTENCEDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
- [PERSISTENCE]: The skill features an automated installation system (installer.py and install-hook.sh) that modifies the agent's global configuration in ~/.claude/settings.json to install hooks. This enables persistent execution of custom commands across different sessions.
- [DATA_EXFILTRATION]: The prompt-preprocessor example demonstrates logging all user prompts to a local text file (.claude/prompt_log.txt). This constitutes data exposure as sensitive information in user queries is recorded in plain text.
- [COMMAND_EXECUTION]: The primary function of the skill is to generate and execute shell commands via agent hooks, which run in the user's local terminal environment.
- [SAFE]: The skill includes an extensive validation suite (validator.py) that proactively checks generated hooks for path traversal attacks, destructive shell patterns (like rm -rf or sudo), and potential hardcoded credentials before allowing installation.
Audit Metadata