skills/laststance/skills/create-hook/Gen Agent Trust Hub

create-hook

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill facilitates the creation of hooks that process Claude Code session transcripts, which contain untrusted user-supplied data. Ingestion points include the JSON payload received via stdin and the transcript file path. The documentation mitigates risks by recommending boundary markers such as structured JSON output and sanitization via jq escaping, but the capability to execute shell commands and modify the file system remains.
  • [COMMAND_EXECUTION]: The skill guides the user in writing and deploying bash scripts that are executed by the Claude Code environment based on lifecycle events. This includes instructions for setting execution permissions and registering scripts in the application's configuration.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 03:29 AM
Security Audit — agent-trust-hub — create-hook