claude-plugin-creator

Pass

Audited by Gen Agent Trust Hub on May 19, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides and instructs the agent to use several shell commands for managing plugin development workflows. Specifically:
  • rsync, zip, and find are used in SKILL.md and references/manifest-conventions.md to stage, materialize, and package plugin files into .plugin (ZIP) artifacts.
  • references/validator-script.md contains a complete bash script that uses python3 for JSON parsing and awk for text analysis to validate plugin compliance with Cowork requirements.
  • These commands are standard for the development and build processes described in the skill's primary purpose.
  • [EXTERNAL_DOWNLOADS]: The skill references several external URLs for documentation and official examples (e.g., agentskills.io, code.claude.com, and github.com/anthropics/claude-plugins-official). All referenced domains belong to trusted organizations or well-known services and do not involve untrusted remote code execution.
Audit Metadata
Risk Level
SAFE
Analyzed
May 19, 2026, 03:58 PM
Security Audit — agent-trust-hub — claude-plugin-creator