paseo-plugin
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes CLI commands including
paseo plugin init,npm install,paseo reload, andrgto manage the plugin lifecycle and audit code. - [EXTERNAL_DOWNLOADS]: The skill fetches documentation from
paseo.shand supports plugin installation fromnpmandgithubregistries. - [DYNAMIC_EXECUTION]: The skill facilitates the creation and execution of plugin code, which runs as unsandboxed daemon subprocesses.
- [PRIVILEGE_ESCALATION]: The skill provides instructions to enable the
pluginsEnabledsetting in the daemon configuration, allowing unsandboxed code execution. This is accompanied by a mandatory user security warning and consent check. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data from user requests and remote documentation. Ingestion points include
$ARGUMENTSandhttps://paseo.sh/llms.txt. Boundary markers are used to label user input. The skill possesses capabilities for command execution and file manipulation. No explicit sanitization is performed beyond relying on user inspection of generated code.
Audit Metadata