hooks-management
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill is designed to manage lifecycle hooks that execute shell commands or scripts. This is the primary and intended purpose of the skill, and it provides safety-oriented templates to restrict dangerous command execution.
- [EXTERNAL_DOWNLOADS]: Documentation and templates within the skill mention using standard developer tools via
npx(e.g.,prettier,eslint) and installing plugins from the npm registry. These references target well-known, trusted registries for legitimate development tasks. - [INDIRECT_PROMPT_INJECTION]: The skill provides an interface for the agent to ingest user-defined logic into its own configuration files. To mitigate risks, the skill includes a dedicated validation script (
scripts/validate_hooks.py) that checks JSON syntax, regex validity, and schema compliance. - [PERSISTENCE]: The skill manages hooks which are, by definition, a mechanism for persistent automation across agent sessions. The documentation provides clear instructions for the user to review and manage these hooks.
Audit Metadata