Back to skill

Security audit

Hook Guard

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a purpose-aligned safety/guardrail skill, with some activation-scope wording users should review before enabling automatic behavior.

Before installing, review the trigger phrases and any automatic mode settings. Use explicit opt-in or visible guard status if available, so the skill does not unexpectedly change how unrelated tasks are handled.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger phrases are broad enough that normal conversation terms like '安全检查' or '守卫' could activate the skill unexpectedly. Because this skill alters how risky operations are handled and may be configured to run automatically, unintended invocation can change agent behavior in ways the user did not explicitly request.

Vague Triggers

Medium
Confidence
91% confidence
Finding
Allowing the agent to 'self-decide' when extra protection applies creates ambiguous activation boundaries and inconsistent enforcement. In security-sensitive controls, discretionary activation is dangerous because protection may fail to engage when needed or may unexpectedly interfere with unrelated tasks.

Static analysis

No suspicious patterns detected.