laravel-plugin-discovery
Pass
Audited by Gen Agent Trust Hub on Apr 1, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill processes README content and package metadata from third-party Laravel repositories via the
GetPluginDetailsTool. This creates an indirect prompt injection surface where a malicious package author could embed instructions in their README to influence the agent's behavior. - Ingestion points: External package metadata and README content fetched via LaraPlugins MCP.
- Boundary markers: None specified to delimit external content from instructions.
- Capability inventory: The skill does not possess high-risk capabilities such as arbitrary command execution or file system write access.
- Sanitization: No explicit sanitization or filtering of external package content is mentioned.
Audit Metadata