skills/howells/skills/polyplugin/Gen Agent Trust Hub

polyplugin

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides structured instructions for multi-platform plugin development. All external references target official documentation and repositories from trusted organizations, including OpenAI (github.com/openai), Cursor (github.com/cursor, cursor.com), and Anthropic (implied via claude CLI tools).
  • [SAFE]: The skill includes explicit security guardrails that prevent autonomous actions such as publishing, tagging, or pushing code without user consent. It also warns against common pitfalls like making private packages public.
  • [SAFE]: Command execution instructions are limited to standard development workflows, such as claude plugins validate or symlinking directories for local testing. These are typical for the developer persona and do not involve obfuscation or risky shell injections.
  • [SAFE]: No sensitive data access or exfiltration patterns were detected. The skill focuses on metadata reconciliation and manifest schema compliance.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 03:11 PM
Security Audit — agent-trust-hub — polyplugin