hook-stack-evaluator

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted text input (the 'hook') provided by users or external agents. \n
  • Ingestion points: SKILL.md instructs the agent to receive a hook in both 'Interactive Mode' and when 'invoked by an agent'. \n
  • Boundary markers: No explicit delimiters (e.g., XML tags or triple quotes) or 'ignore instructions within input' directives are provided to help the agent distinguish between the data to be evaluated and potential instructions. \n
  • Capability inventory: The skill is granted Read, Write, and Edit permissions via allowed-tools in SKILL.md, which could be exploited if an agent follows instructions embedded in a hook. \n
  • Sanitization: No sanitization, validation, or filtering of the input text is described in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:04 AM
Security Audit — agent-trust-hub — hook-stack-evaluator