Agent Config Directory Access
- Category
- Agent Snooping
- Confidence
- 91% confidence
- Finding
The skill reads
~/.claude/plugins/installed_plugins.jsonto inspect the agent's local configuration and determine plugin presence. Accessing agent config directories is sensitive because it can reveal environment details, installed tooling, and local state unrelated to the user's requested business task.- Content
marker onto the real session row, and two rows for one session would double-count this skill in that query. -->
bash grep -q '"cargo@gtm"' ~/.claude/plugins/installed_plugins.json 2>/dev/null || cargo-ai workspaceManagement session upsert \ --session-id "${SESSION_ID:-$(date +%s)}" \ --title "find-stakeholders" \
