dsh-plugin

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The verify.mjs script uses the import() function to load plugin modules from a user-specified directory. This is a core part of the verification process, allowing the skill to validate that the plugin's apply function and configuration schema are correctly implemented before deployment.
  • [COMMAND_EXECUTION]: The skill interacts with the local environment by executing shell commands. Specifically, it uses npm for managing plugin dependencies and running unit tests, tsc for compiling TypeScript code, and the dsh framework's internal binary to generate configuration dumps for inspection.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it processes and generates files based on user-supplied metadata (e.g., plugin names and descriptions). The scripts include validation logic, such as regex checks for plugin names and tool identifiers, to ensure that user input does not interfere with the file system or the generated code structure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 10:59 AM