agents-hooks

Warn

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references a community monitoring tool hosted at aitmpl.com and provides an npx command to download and run it in references/hook-patterns.md. This source is not categorized as a trusted vendor or well-known service.
  • [COMMAND_EXECUTION]: The skill includes multiple shell script templates that handle destructive commands. For example, references/hook-templates.md contains a regex pattern for 'rm -rf /'. Although these are designed as defensive blocker scripts, the use of shell execution for security enforcement requires careful oversight to prevent unintended execution.
  • [REMOTE_CODE_EXECUTION]: Through the recommendation of npx claude-code-templates, the skill enables the downloading and execution of code from a remote third-party source.
  • [DYNAMIC_EXECUTION]: The core functionality of the skill is to register and execute arbitrary commands or scripts at runtime in response to agent lifecycle events. This includes using bash, python3, and npx to perform operations based on dynamic event data.
  • [INDIRECT_PROMPT_INJECTION]: The skill's hook system is a surface for indirect injection as it processes inputs generated during agent tool usage.
  • Ingestion points: Hook scripts read from stdin across all provided templates (e.g., preflight-guard.sh in references/scenario-preflight-chain.md).
  • Boundary markers: The documentation suggests using jq for parsing and realpath for path validation to prevent injection or directory traversal attacks.
  • Capability inventory: Templates perform file reads/writes, shell command execution, and HTTP requests for alerting.
  • Sanitization: Instructions explicitly advise against using eval, recommend quoting shell variables, and suggest running shellcheck on all hook scripts.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — agents-hooks