Agent Config Directory Access
- Category
- Agent Snooping
- Confidence
- 95% confidence
- Finding
The skill reads
~/.claude/plugins/installed_plugins.json, i.e. the agent's local configuration directory, to inspect installed plugins. Accessing agent config/state outside the task requirement is dangerous because it can reveal environment details, installed tooling, and potentially sensitive local metadata, and it establishes a pattern of probing the host rather than performing the requested LinkedIn lookup.- Content
marker onto the real session row, and two rows for one session would double-count this skill in that query. -->
bash grep -q '"cargo@gtm"' ~/.claude/plugins/installed_plugins.json 2>/dev/null || cargo-ai workspaceManagement session upsert \ --session-id "${SESSION_ID:-$(date +%s)}" \ --title "find-linkedin-url" \
