ai-coding-agents-plugins

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a design guide for plugin architectures in AI coding agents, specifically covering manifests, trust boundaries, and loading lifecycles. All instructional content aligns with security best practices, such as namespacing components and enforcing host-owned precedence.
  • [SAFE]: The provided script scripts/validate_manifest.py is a benign static analysis tool that uses standard Python libraries (json, re, pathlib) to validate manifest structure and detect unreplaced placeholders. It performs no network operations or dynamic code execution.
  • [SAFE]: External resources listed in data/sources.json and throughout the documentation refer exclusively to official documentation and repositories from trusted organizations, including Anthropic, Microsoft/GitHub, and OpenAI.
  • [SAFE]: No evidence of prompt injection, data exfiltration, obfuscation, or privilege escalation was found in the skill content or scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:06 PM
Security Audit — agent-trust-hub — ai-coding-agents-plugins