hooked-ux
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: No evidence of prompt injection, role-play instructions, or attempts to bypass safety filters were detected in the instructions or metadata.
- [DATA_EXFILTRATION]: The skill does not access sensitive local files or perform network operations to exfiltrate data. It contains external links to Amazon for book references, which is common for educational content.
- [REMOTE_CODE_EXECUTION]: The package contains a post-installation script that only logs a message to the console. No remote script execution patterns (e.g., curl | bash) or dynamic code generation from untrusted sources were found.
- [COMMAND_EXECUTION]: No dangerous system commands, privilege escalation attempts (sudo), or persistence mechanisms were detected in the skill files or package scripts.
- [OBFUSCATION]: No hidden content, such as base64-encoded commands, zero-width characters, or homoglyph substitutions, was identified in the analyzed files.
- [EXTERNAL_DOWNLOADS]: The skill does not specify any third-party dependencies or remote downloads that would execute code at runtime.
- [DATA_EXPOSURE]: No hardcoded credentials, API keys, or exposure of private environment variables were found.
- [DYNAMIC_CONTEXT_INJECTION]: The skill does not use dynamic shell interpolation patterns in its instructions to execute commands at load time.
Audit Metadata