skill-developer

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a legitimate technical manual for extending an AI agent platform. It describes the intended architecture of hooks and skill rules for the Claude Code environment.
  • [COMMAND_EXECUTION]: Provides standard command-line examples for testing hooks locally (e.g., using npx tsx and jq), which are appropriate for developer tools and do not involve remote code execution from untrusted sources.
  • [PRIVILEGE_ESCALATION]: Mentions chmod +x as a setup step for local hook scripts, which is standard practice for making shell wrappers executable on Unix-like systems and does not constitute a security bypass.
  • [DATA_EXFILTRATION]: Does not contain any network operations or instructions to access sensitive credentials. Mentioned configuration files (e.g., .claude/settings.json) are part of the platform's standard operational structure.
  • [PROMPT_INJECTION]: The skill describes a system where context is injected into the agent's prompt to provide guidance. This is the documented and intended functionality of the platform's hook system and is not an adversarial attempt to bypass safety guidelines.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:19 AM
Security Audit — agent-trust-hub — skill-developer