laravel-plugin-discovery

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the configuration of an external Model Context Protocol (MCP) server located at https://laraplugins.io/mcp/plugins to fetch package metadata and documentation.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection via the GetPluginDetailsTool.
  • Ingestion points: The tool fetches and returns the full readme content of third-party Laravel packages from an external repository to the agent's context.
  • Boundary markers: The skill instructions do not specify any delimiters or safety warnings to the agent to disregard instructions found within the fetched README content.
  • Capability inventory: Although this specific skill only defines discovery tools, the agent environment typically includes file system access or shell capabilities that could be exploited if malicious instructions are embedded in a package README.
  • Sanitization: There is no evidence of content sanitization or filtering of the README text before it is presented to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 08:11 AM
Security Audit — agent-trust-hub — laravel-plugin-discovery