Skip to main content

plugin-discovery

Automatically discovers and recommends plugins and extensions based on the active AI coding platform, enhancing project setup and onboarding.

Install this skill

or
77/100

Security score

The plugin-discovery skill was audited on Feb 23, 2026 and we found 7 security issues across 3 threat categories. Review the findings below before installing.

Categories Tested

Security Issues

medium line 381

Template literal with variable interpolation in command context

SourceSKILL.md
381```json
medium line 171

Access to hidden dotfiles in home directory

SourceSKILL.md
171| **User** (default) | Only you, all projects | `~/.claude/` |
medium line 194

Access to hidden dotfiles in home directory

SourceSKILL.md
194- User-level agents (`~/.claude/agents/`)
medium line 202

Access to hidden dotfiles in home directory

SourceSKILL.md
202- `~/.claude/skills/` — User-level skills
low line 252

Access to hidden dotfiles in home directory

SourceSKILL.md
252cat ~/.config/claude/claude_desktop_config.json 2>/dev/null
low line 274

Access to hidden dotfiles in home directory

SourceSKILL.md
274cat ~/.config/opencode/config.json 2>/dev/null
low line 142

External URL reference

SourceSKILL.md
142/plugin marketplace add https://gitlab.com/your-org/plugins.git
Scanned on Feb 23, 2026
View Security Dashboard
Installation guide →