write-plugin

Pass

Audited by Gen Agent Trust Hub on Apr 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides detailed instructions on how to use the aptx-ft CLI, specifically demonstrating the use of the --plugin or -p flags to load and execute local JavaScript files as extensions to the core tool.- [PROMPT_INJECTION]: The skill introduces a surface for indirect prompt injection by documenting how plugins ingest and process external OpenAPI specifications. While the documentation provides the mechanism (the ctx.getIr method) to read this data, it does not explicitly provide sanitization logic, which is a common characteristic of developer-focused tooling.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 7, 2026, 12:40 PM