hooks-development
Warn
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill provides numerous templates for creating shell and TypeScript scripts that are executed at runtime as hooks. Several bash templates in
references/hook-templates.mdandreferences/visibility-patterns.mdutilizeeval echo "$FILE_PATH"to expand home directories, which represents a potential command injection vector if the tool-provided file path is maliciously manipulated. - [COMMAND_EXECUTION]: The instructions and references (e.g.,
SKILL.md,references/debugging-guide.md) guide users to execute shell commands and modify file permissions usingchmod +xto enable hook execution. This is consistent with the skill's purpose but involves granting execution privileges to local scripts. - [INDIRECT_PROMPT_INJECTION]: The skill documents an attack surface for indirect prompt injection by providing templates that ingest untrusted tool data via
PAYLOAD=$(cat)and interpolate it into feedback for the agent. 1. Ingestion points: Tool input and output data are read from stdin in templates found inreferences/hook-templates.mdandSKILL.md. 2. Boundary markers: The templates do not include boundary markers or instructions to ignore embedded commands within the processed data. 3. Capability inventory: The documented hooks have the capability to execute arbitrary commands, write to the filesystem, and influence the agent's decision-making loop as described inreferences/lifecycle-reference.md. 4. Sanitization: There is no evidence of sanitization or validation of the ingested tool data before it is returned to the agent context.
Audit Metadata