hookfrisk
Audit agent hooks for unsafe auto-execution of untrusted input.
- Stars
- 0
- Forks
- 0
- Updated
- Updated Jul 7, 2026
Audit agent hooks for unsafe auto-execution of untrusted input.
Hookfrisk inspects agent hooks changed by a diff and looks for untrusted tool output, filenames, or trigger text being piped into a shell, along with patterns such as curl piped to bash. It refuses the done state while an auto-running hook can execute input unsafely, helping catch command-injection and remote-code-execution paths before release. It is intended for Claude Code and compatible coding agents.
Resource types
Use cases
Platforms
Audience
Audit suspension risks in a Claude Code working environment.
Check whether a specific CVE actually applies to your environment.
Public GitHub facts last synced Jul 10, 2026.
Store and inject development secrets through 1Password from Claude Code.
Audit a deployed public app for production gaps missed during coding.