plugin-write

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill does not contain any malicious patterns such as prompt injection, persistence mechanisms, or unauthorized privilege escalation. It serves as a legitimate developer assistant for the DeepSeek Harness ecosystem.\n- [COMMAND_EXECUTION]: The skill provides Node.js scripts (validate-names.mjs and query-registry.mjs) to assist users with plugin metadata validation. These scripts are benign, using standard Node.js APIs to perform local data validation.\n- [EXTERNAL_DOWNLOADS]: The skill facilitates a read-only registry check by fetching a JSON index from a public GitHub repository. This operation is limited to data parsing and does not execute remote code or exfiltrate sensitive information.\n- [INDIRECT_PROMPT_INJECTION]: Documentation for creating tools includes built-in mitigation rules, such as enforcing strict argument validation through Schemas, which helps prevent confusion or injection in the generated plugins.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 06:18 AM