skills/xiaolai/nlpm/writing-hooks/Gen Agent Trust Hub

writing-hooks

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill documents the implementation of dynamic hooks that execute shell scripts and agents at runtime. It provides configuration examples for resolving local script paths and executing them based on tool events.
  • [INDIRECT_PROMPT_INJECTION]: The described hook architecture in SKILL.md creates a potential surface for indirect prompt injection by processing external tool data. (1) Ingestion points: Hook scripts receive toolInput and parameters via stdin in JSON format. (2) Boundary markers: The documentation does not specify the use of delimiters or markers to isolate untrusted input. (3) Capability inventory: Command hooks are executed as shell processes with the ability to perform file operations and block agent tool calls. (4) Sanitization: The provided bash script template demonstrates basic JSON parsing with jq but lacks robust validation or sanitization of input variables before use in shell redirection.
  • [COMMAND_EXECUTION]: The skill includes shell script examples (bash) designed to perform line counting and file validation, illustrating how users can implement local command execution within the agent's hook system.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 02:57 PM
Security Audit — agent-trust-hub — writing-hooks