hook-development
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill provides several bash scripts (
hook-linter.sh,test-hook.sh,validate-hook-schema.sh) intended for development-time validation of hooks. These scripts execute commands as part of their documented utility function (e.g., usingjqto parse JSON ortimeoutto test execution time). - [REMOTE_CODE_EXECUTION]: While
references/advanced.mdmentionscurlfor Slack notifications or database logging, these are provided as pedagogical examples for the user's own implementation and are not executed by the skill itself. The skill does not contain any automatic remote code execution triggers. - [DATA_EXFILTRATION]: Documentation in
references/advanced.mdincludes examples of sending metrics to StatSD or notifications to Slack. These are clearly marked as integration patterns for developers to use in their own plugins and do not constitute exfiltration within this skill. - [PROMPT_INJECTION]: The skill documentation provides examples of 'Prompt-Based Hooks'. These are used to teach the agent how to evaluate safety (e.g., 'Validate file write safety'). There are no instructions that attempt to override the underlying agent's safety guidelines or bypass restrictions.
Audit Metadata