create-cowork-plugin

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use shell commands for packaging the created plugin into a .plugin file (using zip and cp) and for validating the plugin manifest (using claude plugin validate). These operations are part of the core functionality for delivering the final product to the user.
  • [PROMPT_INJECTION]: The skill generates plugin components based on user input provided during the discovery and design phases. This creates an attack surface where malicious user input could potentially be incorporated into the generated plugin's commands or scripts.
  • Ingestion points: User responses during Phase 1 (Discovery) and Phase 3 (Design) are used to populate plugin files.
  • Boundary markers: The instructions do not specify the use of delimiters or warnings to prevent the agent from obeying instructions embedded in the user's design specifications.
  • Capability inventory: The skill uses Write and Edit to create the plugin files and Bash to package them.
  • Sanitization: The workflow does not include a step to sanitize or validate the content of user-provided strings before they are interpolated into the generated plugin files.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 05:59 AM
Security Audit — agent-trust-hub — create-cowork-plugin