Project overview
Hookfrisk inspects agent hooks changed by a diff and looks for untrusted tool output, filenames, or trigger text being piped into a shell, along with patterns such as curl piped to bash. It refuses the done state while an auto-running hook can execute input unsafely, helping catch command-injection and remote-code-execution paths before release. It is intended for Claude Code and compatible coding agents.
Repository facts
- Primary language
- Shell
- License
- MIT
- Repository updated
- Jul 7, 2026
- Default branch
- main
Resource types
General skill
Use cases
Security and privacy
Platforms
Claude Code, Codex, and more
Audience
DevelopersSecurity engineers