agent-plugin-eval

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes manifest files and instructions from untrusted repositories, which could potentially contain malicious prompts designed to influence the agent's evaluation output.
  • Ingestion points: The skill reads plugin.json, mcp.json, and SKILL.md files from the target repository (provided via the target or compare parameters).
  • Boundary markers: The skill includes a 'Safety boundary' section in SKILL.md that explicitly restricts the agent to static auditing and forbids running any bundled executables or scripts from the untrusted source.
  • Capability inventory: The skill utilizes local Python scripts (inspect_plugin.py, score.py) for analysis and scoring, and involves cloning remote repositories using git clone tools.
  • Sanitization: The analysis script scripts/inspect_plugin.py implements path containment checks to prevent directory traversal and performs strict schema validation on manifest fields using regex.
  • [COMMAND_EXECUTION]: The skill executes its own internal Python scripts to perform the audit and calculate scores.
  • Evidence: The workflow involves running python3 scripts/inspect_plugin.py and scripts/score.py. These scripts perform deterministic static analysis and do not execute code from the target repository.
  • [EXTERNAL_DOWNLOADS]: The skill retrieves code from external Git repositories to facilitate its auditing functionality.
  • Evidence: The workflow instructs the agent to clone Git URLs into a temporary directory for inspection. This is a core functional requirement of the auditing tool.
  • Note: The skill also references agent-plugins.org for specification and schema retrieval, which is the official service for the specification being audited.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 08:20 AM
Security Audit — agent-trust-hub — agent-plugin-eval