laravel-plugin-discovery

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to configure a connection to an external Model Context Protocol (MCP) server at https://laraplugins.io/mcp/plugins to provide its search and analysis features.
  • [DATA_EXFILTRATION]: Search keywords, vendor filters, and package names entered by the user are transmitted to the laraplugins.io endpoint during tool execution.
  • [PROMPT_INJECTION]: The skill retrieves untrusted data from an external source, specifically package README files, which constitutes an attack surface for indirect prompt injection. 1. Ingestion points: External README content via GetPluginDetailsTool. 2. Boundary markers: None provided to isolate external content from instructions. 3. Capability inventory: Access to package search and detailed metrics retrieval. 4. Sanitization: No explicit validation or filtering of the remote data is implemented.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 02:47 PM
Security Audit — agent-trust-hub — laravel-plugin-discovery