plugin-packaging

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides structured guidance for creating plugin archives. It does not contain any malicious instructions or obfuscated content.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill includes proactive safety measures. The validation checklist specifically instructs the agent to ensure that no hardcoded secrets, API keys, or .env files are included in the plugin package.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow for collecting and packaging files from external sources (bound plugins). While this creates an ingestion surface for untrusted data, the skill focuses on archival tasks rather than execution. The instructions emphasize validation and sanitization of the package content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 10:14 AM
Security Audit — agent-trust-hub — plugin-packaging