hooks-management

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill is designed to manage lifecycle hooks that execute shell commands or scripts. This is the primary and intended purpose of the skill, and it provides safety-oriented templates to restrict dangerous command execution.
  • [EXTERNAL_DOWNLOADS]: Documentation and templates within the skill mention using standard developer tools via npx (e.g., prettier, eslint) and installing plugins from the npm registry. These references target well-known, trusted registries for legitimate development tasks.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides an interface for the agent to ingest user-defined logic into its own configuration files. To mitigate risks, the skill includes a dedicated validation script (scripts/validate_hooks.py) that checks JSON syntax, regex validity, and schema compliance.
  • [PERSISTENCE]: The skill manages hooks which are, by definition, a mechanism for persistent automation across agent sessions. The documentation provides clear instructions for the user to review and manage these hooks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 02:48 AM
Security Audit — agent-trust-hub — hooks-management