handbook-discover

Pass

Audited by Gen Agent Trust Hub on Mar 27, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/discover.py executes the claude CLI tool using subprocess.run to retrieve plugin installation status and marketplace locations. These calls use the safe list-based argument format and target legitimate plugin management functionality.
  • [SAFE]: The skill performs read-only file system operations within the resolved marketplace repository root to identify plugin components such as skills, agents, and MCP servers. It does not access sensitive system files or perform unauthorized network operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 27, 2026, 07:46 PM