create-cowork-plugin
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use shell commands for packaging the created plugin into a
.pluginfile (usingzipandcp) and for validating the plugin manifest (usingclaude plugin validate). These operations are part of the core functionality for delivering the final product to the user. - [PROMPT_INJECTION]: The skill generates plugin components based on user input provided during the discovery and design phases. This creates an attack surface where malicious user input could potentially be incorporated into the generated plugin's commands or scripts.
- Ingestion points: User responses during Phase 1 (Discovery) and Phase 3 (Design) are used to populate plugin files.
- Boundary markers: The instructions do not specify the use of delimiters or warnings to prevent the agent from obeying instructions embedded in the user's design specifications.
- Capability inventory: The skill uses
WriteandEditto create the plugin files andBashto package them. - Sanitization: The workflow does not include a step to sanitize or validate the content of user-provided strings before they are interpolated into the generated plugin files.
Audit Metadata