claude-plugin-creator
Pass
Audited by Gen Agent Trust Hub on May 19, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides and instructs the agent to use several shell commands for managing plugin development workflows. Specifically:
rsync,zip, andfindare used inSKILL.mdandreferences/manifest-conventions.mdto stage, materialize, and package plugin files into.plugin(ZIP) artifacts.references/validator-script.mdcontains a complete bash script that usespython3for JSON parsing andawkfor text analysis to validate plugin compliance with Cowork requirements.- These commands are standard for the development and build processes described in the skill's primary purpose.
- [EXTERNAL_DOWNLOADS]: The skill references several external URLs for documentation and official examples (e.g.,
agentskills.io,code.claude.com, andgithub.com/anthropics/claude-plugins-official). All referenced domains belong to trusted organizations or well-known services and do not involve untrusted remote code execution.
Audit Metadata