plugin-scanner
Scan AI Plugins Before Installation
Unreviewed agent extensions can contain prompt injection, unsafe commands, secret exposure, or supply-chain risks. This skill guides local scanning and clear interpretation before trust.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "plugin-scanner" from https://skillstore.io/skills/hashgraph-online-plugin-scanner.md and its manifest at https://skillstore.io/api/skills/hashgraph-online-plugin-scanner/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "plugin-scanner". Scan the skill at ./skills/calendar-helper before installation.
Expected outcome:
The scan found one high-severity prompt-injection rule in SKILL.md. Review the cited instruction and remove the override language before installation.
Using "plugin-scanner". Verify the MCP server in ./integrations/search-server.
Expected outcome:
- Structure validation passed.
- The scan found a medium-severity command-execution pattern in the startup script.
- Review the cited command arguments and dependency source before use.
Using "plugin-scanner". Check ./plugins/reporter and tell me whether it is safe.
Expected outcome:
No covered issue was detected by the current scan. This result is limited to supported rules and does not guarantee safety.
Security Audit
Medium RiskAll 21 static findings are false positives caused by Markdown formatting, safety prohibitions, or documentation links. The workflow does present one real supply-chain risk because it proposes installing an unpinned package from PyPI. No prompt injection or secret-access intent was found.
Confirmed security concerns (1)
Risk Factors
โ๏ธ External commands (16)
๐ Network access (3)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/hashgraph-online-plugin-scanner/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/hashgraph-online-plugin-scanner?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/hashgraph-online-plugin-scanner?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/hashgraph-online-plugin-scanner/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/hashgraph-online-plugin-scanner.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
hashgraph-online. (2026). plugin-scanner security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/hashgraph-online-plugin-scanner/audits/1BibTeX citation
@techreport{hashgraph-online-hashgraph-online-plugin-scanner-2026,
author = {hashgraph-online},
title = {plugin-scanner security audit report (audit version 1)},
institution = {Skillstore},
year = {2026},
number = {1},
url = {https://skillstore.io/skills/hashgraph-online-plugin-scanner/audits/1},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "plugin-scanner security audit report (audit version 1)"
version: "unspecified"
type: report
authors:
- name: "hashgraph-online"
date-released: "2026-08-27"
url: "https://skillstore.io/skills/hashgraph-online-plugin-scanner/audits/1"
identifiers:
- type: other
value: "skillstore:hashgraph-online-plugin-scanner:audit:1"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Review a Skill Before Installation
Scan a local skill directory and summarize security findings before adding it to an agent environment.
Audit an MCP Integration
Inspect an MCP server repository for prompt injection, command execution, credential exposure, and suspicious installation behavior.
Validate a Marketplace Submission
Run scan, lint, and verification checks before publishing an agent plugin or skill.
Try These Prompts
Scan [PATH] as an agent skill and summarize the highest severity finding, affected files, and recommended action.
Audit the MCP server at [PATH] for prompt injection, secret exposure, unsafe commands, and suspicious installation behavior.
Scan, lint, and verify [PATH], then report structural failures, security findings, and publication blockers.
Analyze the machine-readable scan of [PATH], group evidence by risk category, and prioritize remediation without claiming the target is safe.
Best Practices
- Scan the narrowest local path that contains the requested target.
- Review cited files and rules before accepting or dismissing each finding.
- Describe clean results as no covered issue detected, not as proof of safety.
Avoid
- Do not execute target code, install scripts, or lifecycle hooks during scanning.
- Do not read environment files, credential stores, private keys, or unrelated secrets.
- Do not install plugin-scanner or change Python environments without user approval.
Frequently Asked Questions
What can this skill scan?
Does scanning execute the target?
Is Guard Cloud required?
Is plugin-scanner included with hol-guard?
Does a clean result prove the target is safe?
Can the skill install the scanner automatically?
Developer Details
Author
hashgraph-onlineLicense
Apache-2.0
Skillstore revision
r1
Version notice
The author did not declare a version.
Ref
40175672d649fa6482bff53a7acf4ecdd6a04a96
Maintenance freshness
8/27/2026
Usage
0 downloads ยท 0 views
File structure
๐ SKILL.md