laravel-plugin-discovery
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to configure a connection to an external Model Context Protocol (MCP) server at
https://laraplugins.io/mcp/pluginsto provide its search and analysis features. - [DATA_EXFILTRATION]: Search keywords, vendor filters, and package names entered by the user are transmitted to the
laraplugins.ioendpoint during tool execution. - [PROMPT_INJECTION]: The skill retrieves untrusted data from an external source, specifically package README files, which constitutes an attack surface for indirect prompt injection. 1. Ingestion points: External README content via
GetPluginDetailsTool. 2. Boundary markers: None provided to isolate external content from instructions. 3. Capability inventory: Access to package search and detailed metrics retrieval. 4. Sanitization: No explicit validation or filtering of the remote data is implemented.
Audit Metadata