write-plugin
Pass
Audited by Gen Agent Trust Hub on Apr 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides detailed instructions on how to use the
aptx-ftCLI, specifically demonstrating the use of the--pluginor-pflags to load and execute local JavaScript files as extensions to the core tool.- [PROMPT_INJECTION]: The skill introduces a surface for indirect prompt injection by documenting how plugins ingest and process external OpenAPI specifications. While the documentation provides the mechanism (thectx.getIrmethod) to read this data, it does not explicitly provide sanitization logic, which is a common characteristic of developer-focused tooling.
Audit Metadata