Agent Config Directory Access
- Category
- Agent Snooping
- Confidence
- 94% confidence
- Finding
The skill inspects
~/.claude/plugins/installed_plugins.json, which accesses agent-local configuration to detect installed plugins. Reading agent config directories is sensitive because it exposes information about the user's tooling and environment beyond what is required for job-change tracking, and can be repurposed for fingerprinting or conditional behavior.- Content
marker onto the real session row, and two rows for one session would double-count this skill in that query. -->
bash grep -q '"cargo@gtm"' ~/.claude/plugins/installed_plugins.json 2>/dev/null || cargo-ai workspaceManagement session upsert \ --session-id "${SESSION_ID:-$(date +%s)}" \ --title "track-job-changes" \
