plugin-discovery
Automatically discovers and recommends plugins and extensions based on the active AI coding platform, enhancing project setup and onboarding.
Install this skill
or
77/100
Security score
The plugin-discovery skill was audited on Feb 23, 2026 and we found 7 security issues across 3 threat categories. Review the findings below before installing.
Categories Tested
Security Issues
medium line 381
Template literal with variable interpolation in command context
SourceSKILL.md
| 381 | ```json |
medium line 171
Access to hidden dotfiles in home directory
SourceSKILL.md
| 171 | | **User** (default) | Only you, all projects | `~/.claude/` | |
medium line 194
Access to hidden dotfiles in home directory
SourceSKILL.md
| 194 | - User-level agents (`~/.claude/agents/`) |
medium line 202
Access to hidden dotfiles in home directory
SourceSKILL.md
| 202 | - `~/.claude/skills/` — User-level skills |
low line 252
Access to hidden dotfiles in home directory
SourceSKILL.md
| 252 | cat ~/.config/claude/claude_desktop_config.json 2>/dev/null |
low line 274
Access to hidden dotfiles in home directory
SourceSKILL.md
| 274 | cat ~/.config/opencode/config.json 2>/dev/null |
low line 142
External URL reference
SourceSKILL.md
| 142 | /plugin marketplace add https://gitlab.com/your-org/plugins.git |
Scanned on Feb 23, 2026
View Security Dashboard