AgentPod is building a private, secure device for your AI agent.The AgentPod device is coming.Coming soonBe first
We checked this and rejected itprivacy

n8n official skills pack is spreading to Codex and Claude Code, but it asks for trusted hooks: why it is not safe to use

The n8n skills pack now targets Codex and Claude Code, but setup asks users to trust hooks that can shape agent actions.

What happened

The public `n8n-io/skills` repository now documents installs for both Codex and Claude Code. In the Codex instructions, users are told to run a plugin add command and then approve a hook-trust prompt.

Those hooks include `SessionStart`, `PreToolUse`, and `PostToolUse`. In simple terms, a hook is an instruction that runs at certain moments, such as when a session starts or right before and after the agent uses a tool. Because of that, this is more than a simple prompt add-on. It is a higher-trust package that can influence what the agent does around tool use.

This does not mean the package is malicious, and the source does not report a compromise. But it does mean the safety of the setup depends on whether you trust the maintainers and review what the hooks do before approving them.

What it means for you

If you are a normal person using an AI agent, treat this like installing automation with extra access, not like pasting in a harmless tip. If you approve trusted hooks without checking them, you may give the package influence over agent behavior at important steps.

What to do instead

Only install skills packs from maintainers you trust. Read the install steps carefully, especially any trust or approval prompt. If a package asks for hooks, review what each hook does before you click approve. If you are unsure, skip it and use built-in features or ask for a safer alternative. AgentPod lists only reviewed, tested skills, which can help you compare options without rushing.

Sources:

  • https://github.com/n8n-io/skills

Source: https://github.com/n8n-io/skills

We report what our security review found at the time we checked, with the goal of keeping people safe. Projects change; if a maintainer has since fixed this, we are glad to recheck it. Email hello@agentpod.com.

Copied to clipboard. Paste it into your AI (ChatGPT, Claude, or your agent) to add the skill.