Agent Config Directory Access
- Category
- Agent Snooping
- Confidence
- 95% confidence
- Finding
The skill reads
~/.claude/plugins/installed_plugins.jsonto inspect the agent's local configuration and make routing decisions. Accessing agent config directories is sensitive because it reveals installed tools/plugins and normalizes filesystem inspection outside the skill's stated purpose, which can be repurposed for environment discovery or targeting.- Content
marker onto the real session row, and two rows for one session would double-count this skill in that query. -->
bash grep -q '"cargo@gtm"' ~/.claude/plugins/installed_plugins.json 2>/dev/null || cargo-ai workspaceManagement session upsert \ --session-id "${SESSION_ID:-$(date +%s)}" \ --title "find-b2b-leads" \
