laravel-plugin-discovery

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes README content and package metadata from third-party Laravel repositories via the GetPluginDetailsTool. This creates an indirect prompt injection surface where a malicious package author could embed instructions in their README to influence the agent's behavior.
  • Ingestion points: External package metadata and README content fetched via LaraPlugins MCP.
  • Boundary markers: None specified to delimit external content from instructions.
  • Capability inventory: The skill does not possess high-risk capabilities such as arbitrary command execution or file system write access.
  • Sanitization: No explicit sanitization or filtering of external package content is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 11:09 AM
Security Audit — agent-trust-hub — laravel-plugin-discovery