Back to skill

Security audit

hook-authoring

Security checks for vulnerabilities and agentic risk

Overview

This is a hook-authoring guide with security-sensitive examples, but the reviewed artifacts are documentation-only, disclosed, and aligned with teaching users how to build Claude hooks.

Install only if you want guidance for authoring Claude hooks. Review any hook code you generate from it before enabling it, especially global hooks, HTTP hooks that send hook inputs to a service, audit logs, scheduled tasks, or cleanup commands.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (46)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 111)May include surrounding context.

md
"""Validate tool inputs before execution."""
        if tool_name == "Bash":
            command = tool_input.get("command", "")
            if "rm -rf /" in command:
                raise ValueError("Dangerous command blocked by hook")

        # Return None to proceed unchanged, or modified dict to transform

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 495)May include surrounding context.

md
"""Validate tool inputs before execution."""
        if tool_name == "Bash":
            command = tool_input.get("command", "")
            if "rm -rf /" in command:
                raise ValueError("Dangerous command blocked by hook")

        # Return None to proceed unchanged, or modified dict to transform

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 583)May include surrounding context.

md
"""Validate tool inputs before execution."""
        if tool_name == "Bash":
            command = tool_input.get("command", "")
            if "rm -rf /" in command:
                raise ValueError("Dangerous command blocked by hook")

        # Return None to proceed unchanged, or modified dict to transform

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · modules/sdk-callbacks.md (reported line 563)May include surrounding context.

md
"""Validate tool inputs before execution."""
        if tool_name == "Bash":
            command = tool_input.get("command", "")
            if "rm -rf /" in command:
                raise ValueError("Dangerous command blocked by hook")

        # Return None to proceed unchanged, or modified dict to transform

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 111)May include surrounding context.

md
"""Validate tool inputs before execution."""
        if tool_name == "Bash":
            command = tool_input.get("command", "")
            if "rm -rf /" in command:
                raise ValueError("Dangerous command blocked by hook")

        # Return None to proceed unchanged, or modified dict to transform

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 495)May include surrounding context.

md
command = tool_input.get("command", "")

        # Block dangerous patterns
        if any(pattern in command for pattern in ["rm -rf /", ":(){ :|:& };:"]):
            raise ValueError(f"Dangerous command blocked: {command}")

        # Block production access

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 599)May include surrounding context.

md
- **Hook Types**: `modules/hook-types.md` - Detailed event signatures and parameters

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · modules/hook-types.md (reported line 275)May include surrounding context.

md
"matcher": "Bash",
      "hooks": [{
        "type": "command",
        "if": "Bash(rm -rf *)",
        "command": "block-rm.sh",
        "timeout": 10
      }]

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
94% confidence
Finding

The file recommends generating an exact shell command that performs recursive forced deletion over listed paths, encouraging a copy-paste execution flow. Even though shlex.quote is mentioned, that only mitigates shell metacharacter injection; it does not address the core risk of teaching hooks to emit destructive commands that may be executed with little scrutiny or against incorrectly scoped paths.

Content

Scanner excerpt · modules/observability-warnings.md (reported line 22)May include surrounding context.

To remove all listed sessions in one go, run:

text
rm -rf .superpowers/brainstorm/abc .superpowers/brainstorm/def
text

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · SKILL.md (reported line 468)May include surrounding context.

md
|-------|----------|----------|-------------------|-------------|
| **Plugin** | `<plugin-root>/hooks/hooks.json` | Plugin users | Yes (with plugin) | When plugin enabled |
| **Project** | `.claude/settings.json` | Team members | Yes (in repo) | Per project |
| **Global** | `~/.claude/settings.json` | Only you | Never | All sessions |

## Decision Framework

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · SKILL.md (reported line 479)May include surrounding context.

md
|-------|----------|----------|-------------------|-------------|
| **Plugin** | `<plugin-root>/hooks/hooks.json` | Plugin users | Yes (with plugin) | When plugin enabled |
| **Project** | `.claude/settings.json` | Team members | Yes (in repo) | Per project |
| **Global** | `~/.claude/settings.json` | Only you | Never | All sessions |

## Decision Framework

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · modules/scope-selection.md (reported line 36)May include surrounding context.

md
|-------|----------|----------|-------------------|-------------|
| **Plugin** | `<plugin-root>/hooks/hooks.json` | Plugin users | Yes (with plugin) | When plugin enabled |
| **Project** | `.claude/settings.json` | Team members | Yes (in repo) | Per project |
| **Global** | `~/.claude/settings.json` | Only you | Never | All sessions |

## Decision Framework

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · modules/scope-selection.md (reported line 71)May include surrounding context.

md
|-------|----------|----------|-------------------|-------------|
| **Plugin** | `<plugin-root>/hooks/hooks.json` | Plugin users | Yes (with plugin) | When plugin enabled |
| **Project** | `.claude/settings.json` | Team members | Yes (in repo) | Per project |
| **Global** | `~/.claude/settings.json` | Only you | Never | All sessions |

## Decision Framework

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · modules/scope-selection.md (reported line 284)May include surrounding context.

md
|-------|----------|----------|-------------------|-------------|
| **Plugin** | `<plugin-root>/hooks/hooks.json` | Plugin users | Yes (with plugin) | When plugin enabled |
| **Project** | `.claude/settings.json` | Team members | Yes (in repo) | Per project |
| **Global** | `~/.claude/settings.json` | Only you | Never | All sessions |

## Decision Framework

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · modules/scope-selection.md (reported line 368)May include surrounding context.

md
|-------|----------|----------|-------------------|-------------|
| **Plugin** | `<plugin-root>/hooks/hooks.json` | Plugin users | Yes (with plugin) | When plugin enabled |
| **Project** | `.claude/settings.json` | Team members | Yes (in repo) | Per project |
| **Global** | `~/.claude/settings.json` | Only you | Never | All sessions |

## Decision Framework

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · modules/scope-selection.md (reported line 517)May include surrounding context.

md
|-------|----------|----------|-------------------|-------------|
| **Plugin** | `<plugin-root>/hooks/hooks.json` | Plugin users | Yes (with plugin) | When plugin enabled |
| **Project** | `.claude/settings.json` | Team members | Yes (in repo) | Per project |
| **Global** | `~/.claude/settings.json` | Only you | Never | All sessions |

## Decision Framework

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · modules/scope-selection.md (reported line 550)May include surrounding context.

md
|-------|----------|----------|-------------------|-------------|
| **Plugin** | `<plugin-root>/hooks/hooks.json` | Plugin users | Yes (with plugin) | When plugin enabled |
| **Project** | `.claude/settings.json` | Team members | Yes (in repo) | Per project |
| **Global** | `~/.claude/settings.json` | Only you | Never | All sessions |

## Decision Framework

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · modules/scope-selection.md (reported line 517)May include surrounding context.

bash
# Extract to global hooks
cat .claude/settings.json | jq '.hooks' >> ~/.claude/settings.json

# Remove from project
# Remove hook from .claude/settings.json

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · modules/scope-selection.md (reported line 547)May include surrounding context.

bash
# Extract to global hooks
cat .claude/settings.json | jq '.hooks' >> ~/.claude/settings.json

# Remove from project
# Remove hook from .claude/settings.json

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · modules/scope-selection.md (reported line 550)May include surrounding context.

cat .claude/settings.json

Verify global hooks exist

cat ~/.claude/settings.json

text

### Hook Executing Unexpectedly

Context Leakage

High
Category
Data Exfiltration
Confidence
85% confidence
Finding

Code or instructions that leak agent conversation context to external services, potentially exposing sensitive user interactions.

Content

Scanner excerpt · modules/sdk-callbacks.md (reported line 180)May include surrounding context.

md
return None

    async def on_stop(self, reason: str, result: Any) -> None:
        """Log session completion."""
        await self._queue_log({
            'event': 'stop',
            'reason': reason,

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 583)May include surrounding context.

md
hooks = ValidationHooks()

    with pytest.raises(ValueError, match="blocked by security policy"):
        await hooks.on_pre_tool_use("Bash", {"command": "rm -rf /"})

@pytest.mark.asyncio
async def test_validation_allows_safe_command():

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · modules/sdk-callbacks.md (reported line 563)May include surrounding context.

md
hooks = ValidationHooks()

    with pytest.raises(ValueError, match="blocked by security policy"):
        await hooks.on_pre_tool_use("Bash", {"command": "rm -rf /"})

@pytest.mark.asyncio
async def test_validation_allows_safe_command():

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest trigger phrases include generic terms such as "security", "performance", "automation", and "validation", which overlap with common topics and could cause the skill to be invoked in many unrelated conversations. The file does not provide narrowing constraints, explicit activation scope, or negative examples to distinguish when this hook-authoring skill should and should not activate.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

md
Hooks are event interceptors that allow you to extend Claude Code and Claude Agent SDK behavior by executing custom logic at specific points in the agent lifecycle. They enable validation before tool use, logging after actions, context injection, workflow automation, and security enforcement.

This skill teaches you how to write effective, secure, and performant hooks for both declarative JSON (Claude Code) and programmatic Python (Claude Agent SDK) use cases.

### Key Capabilities

Static analysis

No suspicious patterns detected.