hooks-development

Warn

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill provides numerous templates for creating shell and TypeScript scripts that are executed at runtime as hooks. Several bash templates in references/hook-templates.md and references/visibility-patterns.md utilize eval echo "$FILE_PATH" to expand home directories, which represents a potential command injection vector if the tool-provided file path is maliciously manipulated.
  • [COMMAND_EXECUTION]: The instructions and references (e.g., SKILL.md, references/debugging-guide.md) guide users to execute shell commands and modify file permissions using chmod +x to enable hook execution. This is consistent with the skill's purpose but involves granting execution privileges to local scripts.
  • [INDIRECT_PROMPT_INJECTION]: The skill documents an attack surface for indirect prompt injection by providing templates that ingest untrusted tool data via PAYLOAD=$(cat) and interpolate it into feedback for the agent. 1. Ingestion points: Tool input and output data are read from stdin in templates found in references/hook-templates.md and SKILL.md. 2. Boundary markers: The templates do not include boundary markers or instructions to ignore embedded commands within the processed data. 3. Capability inventory: The documented hooks have the capability to execute arbitrary commands, write to the filesystem, and influence the agent's decision-making loop as described in references/lifecycle-reference.md. 4. Sanitization: There is no evidence of sanitization or validation of the ingested tool data before it is returned to the agent context.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 26, 2026, 04:12 PM
Security Audit — agent-trust-hub — hooks-development