Skip to content

feat(tui): security assessment before plugin install #293

@christso

Description

@christso

Context

Follow-up from #288 (proposal #7).

npx skills shows a security risk assessment from Gen/Socket/Snyk before confirming installation. allagents has no equivalent trust signal before plugin installation.

Proposal

Consider adding a security/trust signal before plugin installation, especially for marketplace plugins. Could include:

  • Source verification (GitHub stars, last update date)
  • Dependency audit summary
  • Integration with security scanning services

Effort

High — requires integrating with external security APIs or building a trust heuristic.

References

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions