handbook-discover
Pass
Audited by Gen Agent Trust Hub on Mar 27, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/discover.pyexecutes theclaudeCLI tool usingsubprocess.runto retrieve plugin installation status and marketplace locations. These calls use the safe list-based argument format and target legitimate plugin management functionality. - [SAFE]: The skill performs read-only file system operations within the resolved marketplace repository root to identify plugin components such as skills, agents, and MCP servers. It does not access sensitive system files or perform unauthorized network operations.
Audit Metadata