plugin-packaging
Pass
Audited by Gen Agent Trust Hub on Aug 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides structured guidance for creating plugin archives. It does not contain any malicious instructions or obfuscated content.
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill includes proactive safety measures. The validation checklist specifically instructs the agent to ensure that no hardcoded secrets, API keys, or
.envfiles are included in the plugin package. - [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow for collecting and packaging files from external sources (bound plugins). While this creates an ingestion surface for untrusted data, the skill focuses on archival tasks rather than execution. The instructions emphasize validation and sanitization of the package content.
Audit Metadata