hooked-ux

Pass

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No evidence of prompt injection, role-play instructions, or attempts to bypass safety filters were detected in the instructions or metadata.
  • [DATA_EXFILTRATION]: The skill does not access sensitive local files or perform network operations to exfiltrate data. It contains external links to Amazon for book references, which is common for educational content.
  • [REMOTE_CODE_EXECUTION]: The package contains a post-installation script that only logs a message to the console. No remote script execution patterns (e.g., curl | bash) or dynamic code generation from untrusted sources were found.
  • [COMMAND_EXECUTION]: No dangerous system commands, privilege escalation attempts (sudo), or persistence mechanisms were detected in the skill files or package scripts.
  • [OBFUSCATION]: No hidden content, such as base64-encoded commands, zero-width characters, or homoglyph substitutions, was identified in the analyzed files.
  • [EXTERNAL_DOWNLOADS]: The skill does not specify any third-party dependencies or remote downloads that would execute code at runtime.
  • [DATA_EXPOSURE]: No hardcoded credentials, API keys, or exposure of private environment variables were found.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill does not use dynamic shell interpolation patterns in its instructions to execute commands at load time.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 7, 2026, 05:42 AM
Security Audit — agent-trust-hub — hooked-ux