pluggy-doctor

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches official documentation from docs.pluggy.ai via an MCP or WebFetch of an llms.txt index. These are well-known resources belonging to the vendor (Pluggy) and are used solely for the stated purpose of code review.
  • [COMMAND_EXECUTION]: The skill mentions command-line instructions (e.g., claude mcp add) but does not execute them automatically. They are provided as documentation to the user for setting up the environment.
  • [PROMPT_INJECTION]: The skill instructions contain strong formatting and guidance but do not attempt to bypass AI safety filters or override system-level instructions in a malicious way. The use of 'Golden rule' and 'Requirement' phrases are internal logic for the code review workflow.
  • [DATA_EXFILTRATION]: No evidence of sensitive data exfiltration. The skill reads local integration files for analysis but only sends queries to the official documentation endpoints specified by the vendor.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 10:27 AM
Security Audit — agent-trust-hub — pluggy-doctor