skills/q00/openclip/oc-hook-finder/Gen Agent Trust Hub

oc-hook-finder

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external content from transcript.json and analysis.json files. These files represent an attack surface where instructions embedded in the media text could attempt to override the agent's behavior.
  • Ingestion points: The agent is instructed to read content from <PROJECT>/transcript.json and <PROJECT>/analysis.json (SKILL.md).
  • Boundary markers: There are no explicit instructions to use delimiters or ignore instructions embedded within the transcript data.
  • Capability inventory: The skill is granted access to the Bash and Read tools, which provides a high-impact execution environment if an injection is successful.
  • Sanitization: The instructions do not mention any validation or filtering of the content read from the transcript files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:34 PM
Security Audit — agent-trust-hub — oc-hook-finder