hookify-rules

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill documents a rule-based system designed to ingest and process untrusted data from multiple local development sources.
  • Ingestion points: The 'Hookify' system, as documented in SKILL.md, processes bash commands, file paths, file contents (edit/write operations), and user prompts.
  • Boundary markers: The documentation does not specify the use of boundary markers or delimiters to isolate untrusted content from the rule logic.
  • Capability inventory: The system can trigger automated warning messages or block operations (e.g., file writes, bash commands) based on matching patterns in the ingested data.
  • Sanitization: No explicit sanitization or validation of the external content is mentioned beyond regex pattern matching.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — hookify-rules