hermes-plugin-evaluation
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The skill consists entirely of instructional Markdown and metadata. It does not include any scripts, binaries, or automated installation steps.- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and evaluate third-party plugin repositories, including files like README, plugin.yaml, and configuration lockfiles. This creates a surface where the agent processes untrusted data. However, the skill explicitly mandates a safe workflow: it instructs the agent to inspect the repository without installing it and emphasizes verifying data paths and external tunnels. The potential for indirect prompt injection is a known risk factor for any skill that reads external content, but it is minimized here by the skill's focus on analysis rather than execution.
Audit Metadata