plugin-creator
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions involve executing local Python scripts to automate filesystem operations for plugin scaffolding.
- Evidence:
SKILL.mdcontains instructions for the agent to runscripts/create_basic_plugin.pyandscripts/validate_plugin.pyto create and verify plugin directories and manifests. - [PROMPT_INJECTION]: The skill provides specific formatting rules for deep links, requesting they be displayed as Markdown links instead of raw URLs.
- Evidence:
SKILL.mdinstructs the agent to use Markdown links likeView <name>forcodex://URLs. This is a platform-specific UI guideline for app handoffs rather than a malicious attempt to conceal the protocol from the user.
Audit Metadata