dsh-plugin-publisher

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes several CLI tools to perform its tasks, including pnpm for package management and building, git for repository management, and a custom dsh CLI for plugin operations.
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it reads and processes external plugin source code, which may contain instructions that could influence the agent's behavior during the build and publish process.
  • Ingestion points: The skill ingests data from local plugin source files identified by the user or found in specified development directories.
  • Boundary markers: The skill lacks explicit boundary markers or instructions to treat the content of the plugin files as untrusted data.
  • Capability inventory: The agent has the ability to execute shell commands (pnpm build, pnpm install) and interact with network services (pnpm publish, git push).
  • Sanitization: No specific sanitization or isolation mechanisms are mentioned for handling the plugin source code before processing it through the build pipeline.
  • [EXTERNAL_DOWNLOADS]: The skill instructions include fetching and installing the skill itself via npx or git clone from the official vendor repository on GitHub, which is a standard distribution method for this tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 10:06 PM
Security Audit — agent-trust-hub — dsh-plugin-publisher