plugin-creator

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions involve executing local Python scripts to automate filesystem operations for plugin scaffolding.
  • Evidence: SKILL.md contains instructions for the agent to run scripts/create_basic_plugin.py and scripts/validate_plugin.py to create and verify plugin directories and manifests.
  • [PROMPT_INJECTION]: The skill provides specific formatting rules for deep links, requesting they be displayed as Markdown links instead of raw URLs.
  • Evidence: SKILL.md instructs the agent to use Markdown links like View <name> for codex:// URLs. This is a platform-specific UI guideline for app handoffs rather than a malicious attempt to conceal the protocol from the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:01 PM
Security Audit — agent-trust-hub — plugin-creator