claude-code-plugin-reference

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides structured documentation for plugin development and maintenance. It contains no executable code or instructions that bypass safety filters.
  • [REMOTE_CODE_EXECUTION]: The document describes the host platform's mechanism for executing hook scripts using JSON payloads over stdin. This is a neutral architectural description and does not initiate unauthorized code execution.
  • [DATA_EXFILTRATION]: No patterns of sensitive data access or unauthorized exfiltration were detected. The mention of environment variables (such as VOW_SHADOW_MODE) refers to documented system configuration practices.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes boundary conditions and specific triggers to ensure the information is applied correctly and to prevent the AI from misinterpreting instructions.
  • [OBFUSCATION]: No hidden text, encoded commands, or homoglyph attacks were found in the content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:05 AM
Security Audit — agent-trust-hub — claude-code-plugin-reference