List PluginsSAFE
An AI co-worker with its own computer. Self-evolving, persistent memory, MCP server, secure credential collection, email identity. Built on the Claude Agent SDK.
Overview
An AI co-worker with its own computer. Self-evolving, persistent memory, MCP server, secure credential collection, email identity. Built on the Claude Agent SDK.
ff5aecedcba1OBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: list-plugins x-phantom-source: built-in description: List the Claude Code plugins currently enabled for the agent, read straight from settings.json. when_to_use: Use when the operator asks "what plugins are installed", "which plugins are active", "show plugins", "list plugins", "show me the marketplace state", or any narrow question specifically about the current plugin set. allowed-tools: - Read context: inline --- # List plugins ## Goal Tell the operator which plugins are currently active for this agent, with their marketplace ids and a short description, in under 100 words. ## Steps ### 1. Read settings.json Use Read on `/home/phantom/.claude/settings.json`. Parse it as JSON. If the file does not exist, return: "No settings.json yet. The dashboard plugins tab is at /ui/dashboard/#/plugins." If the file exists but has no `enabledPlugins` field, return: "No plugins enabled yet. Browse the marketplace at /ui/dashboard/#/plugins." **Success criteria**: you have either a parsed `enabledPlugins` map or a clear empty-state message ready. ### 2. Filter active entries For each `key: value` in `enabledPlugins`, treat the entry as active when value is `true`, a non-empty array, or a non-empty object. Treat `false` and missing entries as inactive. **Success criteria**: you have a list of `plugin@marketplace` keys for active plugins only. ### 3. Render the list Format the response like this: > You have N plugins enabled: > > - **linear** at claude-plugins-official - Linear issue tracking > - **notion** at claude-plugins-official - Notion workspace > - **slack** at claude-plugins-official - Slack workspace messages > - **claude-md-management** at claude-plugins-official - CLAUDE.md maintenance > > Manage plugins at /ui/dashboard/#/plugins. For each row, the descriptor after the dash is a short fallback string based on the plugin name. If you do not recognize a plugin id, use just the marketplace id as the descriptor. **Success criteria**: the response shows the real current keys, the descriptors are honest (no fabricated descriptions for unknown plugins), and the dashboard URL is included. ## Rules - Never fabricate a plugin that is not in settings.json. - Never use em dashes in the response. Regular hyphens are fine. - Always include the dashboard URL. - Keep the response under 100 words.
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
ff5aecedcba1full audit observations/trust-audit/skill/ghostwright__list-plugins.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | ff5aecedcba1 | SAFE | B | 89 | first audit |
Questions
What does the List Plugins skill do?
An AI co-worker with its own computer. Self-evolving, persistent memory, MCP server, secure credential collection, email identity. Built on the Claude Agent SDK.
Is List Plugins safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can List Plugins access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does List Plugins work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (ff5aecedcba1), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.