hooks-designer
Pass
Audited by Gen Agent Trust Hub on May 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill does not contain any malicious code, obfuscation, or unauthorized data access patterns. Its primary purpose is to teach the configuration of local security and workflow hooks.
- [COMMAND_EXECUTION]: Provides shell script templates that use common utilities like
jqandgrepto inspect tool inputs. These scripts are intended to be executed locally by the user's agent to enforce development policies. - [EXTERNAL_DOWNLOADS]: Includes a recipe for auto-linting that references
npx prettier. This utilizes the official npm registry, a well-known service, to ensure code formatting consistency. - [DATA_EXFILTRATION]: Includes an audit logging recipe that writes tool metadata (timestamps, tool names, session IDs) to the local filesystem at
~/.claude/logs/. No network exfiltration or transmission of sensitive data was detected.
Audit Metadata