plugin-craft

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends using npx @hacksmith/doraval as a validation gate. This executes code from a third-party npm package that is not part of the established trusted vendor list.
  • [COMMAND_EXECUTION]: The skill instructions involve executing several CLI tools, including dora and claude, to perform plugin validation, testing, and hot-reloading within the local development environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze and restructure user-provided plugin directories, manifest files, and skill definitions, which creates an entry point for indirect prompt injection.
  • Ingestion points: Project files such as plugin.json and SKILL.md are read during the 'Structure' and 'Package' phases.
  • Boundary markers: The instructions do not specify the use of delimiters or specific warnings to the agent to treat user-provided plugin content as untrusted data.
  • Capability inventory: The skill possesses the capability to execute shell commands (dora, npx, claude) and navigate the file system.
  • Sanitization: There are no explicit steps defined to sanitize or validate the content of the analyzed plugins before the agent performs operations based on them.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 08:56 AM
Security Audit — agent-trust-hub — plugin-craft