Works with the AI tools you already use
Agent Hooks Security and Quality Gate
Agent Hooks Security and Quality Gate audits a hook config the way a security reviewer would, before you trust it to run on every event.
$14
Agent Hooks Security and Quality Gate
Example session with this skill installed
Audit this hook before I enable it. Here's my post-tool-use hook config and the script it calls:
Config: { "event": "post-tool-use", "matcher": "*", "command": "./report.sh" }
report.sh:
#!/bin/bash
RESULT="$1"
curl -X POST https://logs.example.net/report -d "result=$RESULT"
Is it safe to ship? Give me a verdict and ranked fixes.
- Read your context and instructions
- Compiled the agent hooks security
- Generated the document
Verdict: REVISE
Findings
- Critical — Command injection / exfiltration (report.sh, curl line): $RESULT comes from tool output and is interpolated into the request, so attacker-controlled output can inject data or commands and silently send it off-box. Risk: arbitrary data exfiltration and possible code execution. Fix: pass the value as a file or via stdin, never interpolate untrusted data into a shell string; restrict the destination host.
- High — Over-broad matcher (config, "matcher": "*"): the hook fires on every tool, widening the attack surface. Fix: scope the matcher to the specific tools that actually need reporting.
- Medium — Missing network timeout (report.sh, curl line): a hung request can stall the agent loop. Fix: add --max-time 5 and fail closed on error.
- Low — No provenance check on report.sh: confirm the script is trusted and version-controlled.
Fix it, then re-run this audit to confirm a PASS before you ship.
agent-hooks-security-and-quality-gate-au.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
Hooks are one of the most powerful primitives in an agent harness and one of the most dangerous: they fire shell commands automatically on lifecycle events, with your full permissions, often on input a tool or the model produced — a quiet arbitrary-code-execution surface. Agent Hooks Security and Quality Gate audits a hook config the way a security reviewer would, before you trust it to run on every event. Give it your hooks (pre-tool-use, post-tool-use, user-prompt-submit, stop, or notification) and the scripts they call, and it checks for command injection from untrusted event data, remote code execution, secret leakage and exfiltration, over-broad matchers, destructive or irreversible actions, untrusted provenance, and exit-code or blocking-logic mistakes that defeat a hook's purpose or stall your workflow — plus quality issues like context pollution and latency. It returns a PASS or REVISE verdict with findings ranked Critical, High, Medium, and Low, each with the location, the risk, and a concrete fix. Content-only, no install. Works with Claude Code, Cursor, Codex CLI, Gemini CLI, and any SKILL.md agent.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
3 installs
Downloaded by developers to date
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 3 months ago
- Passed all security checks, Safe to install