create
Warn
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill performs extensive shell operations to scaffold plugins, validate structure, and manage releases, invoking tools such as node, npm, git, gh, uv, and moon. Evidence is found throughout SKILL.md and the references/ directory.
- [CREDENTIALS_UNSAFE]: The release workflow retrieves a GitHub authentication token using the
gh auth tokencommand. Passing this sensitive token via environment variables to subprocesses is a risky credential handling pattern. Evidence in references/phase4-release.md. - [INDIRECT_PROMPT_INJECTION]: The skill collects untrusted user input for plugin metadata and interpolates it into shell commands and file paths without explicit sanitization.
- Ingestion points: User responses for plugin name and category in references/phase0-discovery.md.
- Boundary markers: Verification of marketplace.json and directory existence.
- Capability inventory: File writes (mkdir), git operations, and process execution (npm run, uv run).
- Sanitization: No programmatic sanitization is applied to user strings before shell interpolation.
- [DYNAMIC_EXECUTION]: The skill incorporates self-modifying code patterns by instructing the agent to immediately update the SKILL.md file and its references if issues occur during execution. Evidence in SKILL.md under the 'Self-Evolving Skill' section.
Audit Metadata