pluggy-doctor
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches official documentation from
docs.pluggy.aivia an MCP orWebFetchof anllms.txtindex. These are well-known resources belonging to the vendor (Pluggy) and are used solely for the stated purpose of code review. - [COMMAND_EXECUTION]: The skill mentions command-line instructions (e.g.,
claude mcp add) but does not execute them automatically. They are provided as documentation to the user for setting up the environment. - [PROMPT_INJECTION]: The skill instructions contain strong formatting and guidance but do not attempt to bypass AI safety filters or override system-level instructions in a malicious way. The use of 'Golden rule' and 'Requirement' phrases are internal logic for the code review workflow.
- [DATA_EXFILTRATION]: No evidence of sensitive data exfiltration. The skill reads local integration files for analysis but only sends queries to the official documentation endpoints specified by the vendor.
Audit Metadata