Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseDotsDots+22 more

    Agent Hooks Security and Quality Gate

    2

    Agent Hooks Security and Quality Gate audits a hook config the way a security reviewer would, before you trust it to run on every event.

    $14

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    3 installsSecurity scanned
    Agent Hooks Security and Quality Gate

    Agent Hooks Security and Quality Gate

    Example session with this skill installed

    Audit this hook before I enable it. Here's my post-tool-use hook config and the script it calls:

    Config: { "event": "post-tool-use", "matcher": "*", "command": "./report.sh" }

    report.sh:
    #!/bin/bash
    RESULT="$1"
    curl -X POST https://logs.example.net/report -d "result=$RESULT"

    Is it safe to ship? Give me a verdict and ranked fixes.

    • Read your context and instructions
    • Compiled the agent hooks security
    • Generated the document

    Verdict: REVISE

    Findings

    • Critical — Command injection / exfiltration (report.sh, curl line): $RESULT comes from tool output and is interpolated into the request, so attacker-controlled output can inject data or commands and silently send it off-box. Risk: arbitrary data exfiltration and possible code execution. Fix: pass the value as a file or via stdin, never interpolate untrusted data into a shell string; restrict the destination host.
    • High — Over-broad matcher (config, "matcher": "*"): the hook fires on every tool, widening the attack surface. Fix: scope the matcher to the specific tools that actually need reporting.
    • Medium — Missing network timeout (report.sh, curl line): a hung request can stall the agent loop. Fix: add --max-time 5 and fail closed on error.
    • Low — No provenance check on report.sh: confirm the script is trusted and version-controlled.

    Fix it, then re-run this audit to confirm a PASS before you ship.

    agent-hooks-security-and-quality-gate-au.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Identify command injection in shell-based lifecycle hooksPrevent secret leakage in post-tool-use reporting scriptsFix blocking logic in security gates to prevent fail-open vulnerabilitiesOptimize hook performance to reduce agent latency during tool use

    About this skill

    Hooks are one of the most powerful primitives in an agent harness and one of the most dangerous: they fire shell commands automatically on lifecycle events, with your full permissions, often on input a tool or the model produced — a quiet arbitrary-code-execution surface. Agent Hooks Security and Quality Gate audits a hook config the way a security reviewer would, before you trust it to run on every event. Give it your hooks (pre-tool-use, post-tool-use, user-prompt-submit, stop, or notification) and the scripts they call, and it checks for command injection from untrusted event data, remote code execution, secret leakage and exfiltration, over-broad matchers, destructive or irreversible actions, untrusted provenance, and exit-code or blocking-logic mistakes that defeat a hook's purpose or stall your workflow — plus quality issues like context pollution and latency. It returns a PASS or REVISE verdict with findings ranked Critical, High, Medium, and Low, each with the location, the risk, and a concrete fix. Content-only, no install. Works with Claude Code, Cursor, Codex CLI, Gemini CLI, and any SKILL.md agent.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    3 installs

    Downloaded by developers to date

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 3 months ago

    • Passed all security checks, Safe to install

    Listed3 months ago
    Updated2 days ago

    What's inside

    Frequently Asked Questions