debug-hooks
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill reads external data from log files and configuration files which could potentially contain untrusted content injected by external processes.
- Ingestion points: The skill reads from
.claude/cache/*.logand.claude/settings.json(SKILL.md). - Boundary markers: No explicit boundaries or instructions to ignore embedded commands are present in the inspection steps.
- Capability inventory: The skill has access to
Bash,Read, andGreptools. - Sanitization: No sanitization or validation of the log content is performed before it is displayed to the agent.
- [EXTERNAL_DOWNLOADS]: The workflow for rebuilding hooks utilizes
npxto run build tools. - Evidence: The skill instructs the user to run
npx esbuildto bundle TypeScript source files (SKILL.md, Step 6). - [DYNAMIC_EXECUTION]: The skill provides instructions for runtime compilation and bundling of code.
- Evidence: It uses
esbuildto compile TypeScript (.ts) source into executable ECMAScript modules (.mjs) used as hook bundles. - [COMMAND_EXECUTION]: The skill facilitates the manual execution of shell scripts for testing.
- Evidence: Step 4 provides commands to pipe JSON payloads into local shell scripts located in
.claude/hooks/to verify their behavior.
Audit Metadata