laravel-plugin-discovery
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted data from an external provider (LaraPlugins.io), which creates a surface for indirect prompt injection.
- Ingestion points: The
GetPluginDetailsToolfetches package metrics and readme content, whileSearchPluginToolretrieves package descriptions, all of which are external and potentially attacker-controlled content. - Boundary markers: The instructions do not provide explicit delimiters or "ignore embedded instructions" directives to prevent the agent from obeying malicious prompts hidden within fetched package data.
- Capability inventory: The skill does not define dangerous capabilities such as local file writing, shell command execution, or sensitive data access that could be abused via an injection.
- Sanitization: There is no mention of sanitization, filtering, or validation of the external content before it is presented to the agent or the user.
Audit Metadata