enhance-plugins

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes external plugin files and configuration data, which serves as a potential vector for indirect prompt injection if the source files contain malicious instructions.
  • Ingestion points: The skill reads plugin.json, opencode.json, ~/.codex/config.toml, and various files within the plugins/ directory.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat the content of these files as untrusted data or to ignore embedded instructions.
  • Capability inventory: The skill possesses the capability to read local files and write modifications back to the filesystem when the --fix argument is provided.
  • Sanitization: The skill lacks explicit sanitization, validation, or escaping of the content ingested from external plugin files before it is processed by the agent's logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 07:14 AM
Security Audit — agent-trust-hub — enhance-plugins