plugin-creator

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes Python scripts to automate the creation of plugin folders and required JSON manifest files. These operations are performed locally to scaffold development environments.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied plugin names and metadata for inclusion in manifests. It incorporates input normalization using regular expressions to ensure consistent naming conventions and provides a validation script to verify the integrity of the generated files.
  • [DATA_EXFILTRATION]: The skill manages application-specific metadata by reading and writing to configuration files within the user's home directory (e.g., ~/.agents/plugins/marketplace.json). This access is limited to the skill's stated purpose of tracking local plugin installations and does not involve harvesting sensitive credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 03:43 AM
Security Audit — agent-trust-hub — plugin-creator