dsh-plugin-upgrade
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads and executes the
dsh-doctorCLI from the npm registry usingnpm execornpm install. These resources are provided by the skill author (@bruc3van).\n - Evidence:
npm view @bruc3van/dsh-doctor version,npm exec --package=@bruc3van/dsh-doctor@<version>, andnpm install --global @bruc3van/dsh-doctorinreferences/cli-bootstrap.md.\n- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands for Git operations, environment inspection, and DSH plugin management.\n - Evidence: Commands such as
git diff,npm view, anddsh-doctor migrate analyzeare used throughoutSKILL.mdandreferences/source-investigation.md.\n- [DYNAMIC_EXECUTION]: During the verification phase, the skill executes project-defined lifecycle scripts to confirm the success of the migration.\n - Evidence: The agent runs
typecheck,build,test, andpack:checkscripts as defined in the plugin'spackage.json(documented inreferences/verification.md).\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted plugin source code and configuration files, which represents a potential attack surface for indirect prompt injection.\n - Ingestion points: The plugin repository root, including source files (
.ts,.js) and metadata files (package.json, manifests) as specified inSKILL.md.\n - Boundary markers: The skill includes specific logical gates for developer authorization but does not use explicit prompt delimiters to isolate content from the plugin files.\n
- Capability inventory: The skill has the capability to write to the file system (
migrate apply), execute shell commands (npm,git), and download packages via the npm registry.\n - Sanitization: No explicit sanitization or filtering of plugin content is mentioned; the skill relies on the internal logic of the
dsh-doctorCLI and developer oversight of the migration plan.
Audit Metadata