skill-developer
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The documentation provides multiple shell command examples for testing hook activation, such as piping JSON state into scripts via
npx tsxand utilizingcatwith here-docs to simulate tool inputs. These are standard developer testing workflows. - [DYNAMIC_EXECUTION]: The skill guides the creation of TypeScript-based hooks (e.g.,
skill-activation-prompt.ts) that are executed dynamically usingtsxwhen a user submits a prompt or a tool is invoked. This is a core feature of the described platform architecture for implementing project-specific logic. - [INDIRECT_PROMPT_INJECTION]: The hook system is designed to ingest and analyze untrusted data, specifically user prompts and file contents, using regex patterns. Findings regarding this category:
- Ingestion points: User prompts are processed by the
UserPromptSubmithook; file contents and paths are analyzed by thePreToolUsehook. - Boundary markers: The skill documentation suggests using visual separators (e.g., Unicode box-drawing characters) when injecting skill suggestions into the AI's context to help the model distinguish between instructions and the user prompt.
- Capability inventory: The hooks can influence the AI's response by injecting context or blocking critical tools like
EditandWritebased on matching criteria. - Sanitization: The implementation relies on standard regular expression matching to identify relevant topics, providing a controlled way to surface guidance without executing untrusted data as code.
Audit Metadata