plugin-craft
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends using
npx @hacksmith/doravalas a validation gate. This executes code from a third-party npm package that is not part of the established trusted vendor list. - [COMMAND_EXECUTION]: The skill instructions involve executing several CLI tools, including
doraandclaude, to perform plugin validation, testing, and hot-reloading within the local development environment. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze and restructure user-provided plugin directories, manifest files, and skill definitions, which creates an entry point for indirect prompt injection.
- Ingestion points: Project files such as
plugin.jsonandSKILL.mdare read during the 'Structure' and 'Package' phases. - Boundary markers: The instructions do not specify the use of delimiters or specific warnings to the agent to treat user-provided plugin content as untrusted data.
- Capability inventory: The skill possesses the capability to execute shell commands (
dora,npx,claude) and navigate the file system. - Sanitization: There are no explicit steps defined to sanitize or validate the content of the analyzed plugins before the agent performs operations based on them.
Audit Metadata