Skip to main content
Run any Skill in Manus
with one click

hookfrisk

Stars0
Forks0
UpdatedJuly 7, 2026 at 13:36

Frisk your agent hooks for commands that auto-run on untrusted input before you ship them. Triggers automatically when you are about to report a coding task done and your diff added or changed a hook (or on /hookfrisk). A hook fires by itself, with no human in the loop — so a hook that pipes tool output or a file path into a shell, or runs curl | bash, is remote code execution on every trigger. hookfrisk reads only the changed hook definitions, flags the ones that run attacker-influenced input or unsandboxed commands, proposes the safe rewrite, and refuses to say "done" while an auto-firing hook can be turned against you.

Installation

Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.

SKILL.md
readonly