plugin-creator
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes Python scripts to automate the creation of plugin folders and required JSON manifest files. These operations are performed locally to scaffold development environments.
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied plugin names and metadata for inclusion in manifests. It incorporates input normalization using regular expressions to ensure consistent naming conventions and provides a validation script to verify the integrity of the generated files.
- [DATA_EXFILTRATION]: The skill manages application-specific metadata by reading and writing to configuration files within the user's home directory (e.g., ~/.agents/plugins/marketplace.json). This access is limited to the skill's stated purpose of tracking local plugin installations and does not involve harvesting sensitive credentials.
Audit Metadata