skill-developer

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The documentation provides multiple shell command examples for testing hook activation, such as piping JSON state into scripts via npx tsx and utilizing cat with here-docs to simulate tool inputs. These are standard developer testing workflows.
  • [DYNAMIC_EXECUTION]: The skill guides the creation of TypeScript-based hooks (e.g., skill-activation-prompt.ts) that are executed dynamically using tsx when a user submits a prompt or a tool is invoked. This is a core feature of the described platform architecture for implementing project-specific logic.
  • [INDIRECT_PROMPT_INJECTION]: The hook system is designed to ingest and analyze untrusted data, specifically user prompts and file contents, using regex patterns. Findings regarding this category:
  • Ingestion points: User prompts are processed by the UserPromptSubmit hook; file contents and paths are analyzed by the PreToolUse hook.
  • Boundary markers: The skill documentation suggests using visual separators (e.g., Unicode box-drawing characters) when injecting skill suggestions into the AI's context to help the model distinguish between instructions and the user prompt.
  • Capability inventory: The hooks can influence the AI's response by injecting context or blocking critical tools like Edit and Write based on matching criteria.
  • Sanitization: The implementation relies on standard regular expression matching to identify relevant topics, providing a controlled way to surface guidance without executing untrusted data as code.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:31 PM
Security Audit — agent-trust-hub — skill-developer