plugin-publishing
Pass
Audited by Gen Agent Trust Hub on Mar 30, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill documents the process of adding external GitHub repositories as marketplaces and installing plugins using the
/plugincommand. While this involves fetching content from remote sources, it is described as the primary intended function of the platform's plugin system and the examples point to legitimate user-controlled or official repositories.- [COMMAND_EXECUTION]: Provides guidance on using standard Git commands (git add,git commit,git push) for version control and publishing. These commands are instructional and directed at the user's own project management workflow.- [SAFE]: Contains references to official documentation atcode.claude.comand public repositories from a trusted organization (github.com/anthropics/knowledge-work-plugins).- [SAFE]: The YAML frontmatter accurately reflects the tools required for the documented tasks (Bash, File I/O), and the JSON configuration examples follow standard schemas without malicious payloads.
Audit Metadata