claude-code-plugin-reference
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides structured documentation for plugin development and maintenance. It contains no executable code or instructions that bypass safety filters.
- [REMOTE_CODE_EXECUTION]: The document describes the host platform's mechanism for executing hook scripts using JSON payloads over stdin. This is a neutral architectural description and does not initiate unauthorized code execution.
- [DATA_EXFILTRATION]: No patterns of sensitive data access or unauthorized exfiltration were detected. The mention of environment variables (such as VOW_SHADOW_MODE) refers to documented system configuration practices.
- [INDIRECT_PROMPT_INJECTION]: The skill includes boundary conditions and specific triggers to ensure the information is applied correctly and to prevent the AI from misinterpreting instructions.
- [OBFUSCATION]: No hidden text, encoded commands, or homoglyph attacks were found in the content.
Audit Metadata