hermes-plugin-evaluation

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill consists entirely of instructional Markdown and metadata. It does not include any scripts, binaries, or automated installation steps.- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and evaluate third-party plugin repositories, including files like README, plugin.yaml, and configuration lockfiles. This creates a surface where the agent processes untrusted data. However, the skill explicitly mandates a safe workflow: it instructs the agent to inspect the repository without installing it and emphasizes verifying data paths and external tunnels. The potential for indirect prompt injection is a known risk factor for any skill that reads external content, but it is minimized here by the skill's focus on analysis rather than execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 07:55 AM
Security Audit — agent-trust-hub — hermes-plugin-evaluation