Context
Follow-up from #288 (proposal #7).
npx skills shows a security risk assessment from Gen/Socket/Snyk before confirming installation. allagents has no equivalent trust signal before plugin installation.
Proposal
Consider adding a security/trust signal before plugin installation, especially for marketplace plugins. Could include:
- Source verification (GitHub stars, last update date)
- Dependency audit summary
- Integration with security scanning services
Effort
High — requires integrating with external security APIs or building a trust heuristic.
References
Context
Follow-up from #288 (proposal #7).
npx skillsshows a security risk assessment from Gen/Socket/Snyk before confirming installation.allagentshas no equivalent trust signal before plugin installation.Proposal
Consider adding a security/trust signal before plugin installation, especially for marketplace plugins. Could include:
Effort
High — requires integrating with external security APIs or building a trust heuristic.
References