plugin-auditor

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is subject to indirect prompt injection risks because its primary function involves reading and analyzing untrusted content from user-specified plugin directories.
  • Ingestion points: The skill ingests data from external plugin repositories, including all source files, configuration files (plugin.json), and documentation (README.md), using the Read and Grep tools.
  • Boundary markers: There are no explicit instructions or delimiters defined to separate the audited content from the auditor's instructions, nor are there warnings to the agent to ignore instructions embedded within the analyzed data.
  • Capability inventory: Across its instruction set, the skill utilizes Read, Grep, and Bash(cmd:*) capabilities. The inclusion of arbitrary shell execution (Bash) creates a significant risk if the agent is manipulated by instructions found within a file it is auditing.
  • Sanitization: The skill does not implement any validation, escaping, or sanitization of the content it reads from the target plugin directory before processing it for report generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 11:31 AM
Security Audit — agent-trust-hub — plugin-auditor