enhance-plugins
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes external plugin files and configuration data, which serves as a potential vector for indirect prompt injection if the source files contain malicious instructions.
- Ingestion points: The skill reads
plugin.json,opencode.json,~/.codex/config.toml, and various files within theplugins/directory. - Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat the content of these files as untrusted data or to ignore embedded instructions.
- Capability inventory: The skill possesses the capability to read local files and write modifications back to the filesystem when the
--fixargument is provided. - Sanitization: The skill lacks explicit sanitization, validation, or escaping of the content ingested from external plugin files before it is processed by the agent's logic.
Audit Metadata