cc-hooks
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill installs and executes local shell scripts (e.g.,
policy-dispatch.sh,read-budget-guard.sh) as PreToolUse, PostToolUse, and Stop hooks. These scripts are used to monitor, intercept, and validate agent commands according to configured security policies. - [DATA_EXFILTRATION]: The skill records telemetry data to a local file (
~/.agents/ao/guardrail-telemetry.jsonl). The telemetry includes session IDs and SHA-256 hashes of file paths involved in policy violations. This approach preserves privacy by ensuring raw file paths or command contents are never persisted or exfiltrated. - [EXTERNAL_DOWNLOADS]: The documentation references external security tools like DCG (Destructive Command Guard) and RCH (Remote Compilation Helper), and provides recipes for integrating with standard formatters (Prettier, Black, Rustfmt) via system package managers (brew, cargo, npm).
- [SAFE]: The skill implements robust safety features, including fail-open logic that ensures Claude Code remains functional if dependencies like
jqorawkare missing. It also includes recursion checks for Stop hooks to prevent infinite loops and uses temporary files for session-based rate limiting of warning messages.
Audit Metadata