Hooks Automation
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a configuration pattern that interpolates untrusted tool parameters into shell command strings, creating a potential vulnerability surface.\n
- Ingestion points: Data from parameters like
${tool.params.command},${tool.params.file_path}, and${tool.params.task}is injected into shell command templates within the hook configurations described inSKILL.md.\n - Boundary markers: The parameters are wrapped in single quotes (e.g.,
'${tool.params.command}'), which is an insufficient boundary that can be bypassed if the content contains shell metacharacters.\n - Capability inventory: The skill is capable of executing arbitrary shell commands, performing file system operations, and interacting with external MCP servers.\n
- Sanitization: No evidence of input escaping, validation, or sanitization logic is provided in the hook configuration templates to prevent command injection.\n- [COMMAND_EXECUTION]: The skill's primary objective is the automated execution of shell commands via the
npx claude-flowutility in response to agent-triggered development events.\n- [EXTERNAL_DOWNLOADS]: The skill requires the installation of theclaude-flowCLI package from the NPM registry. This is a vendor resource associated with the author 'ruvnet'.
Audit Metadata