plugin-update
Audited by Socket on Aug 14, 2026
2 alerts found:
Securityx2No explicit malware is demonstrated in this fragment because it contains only commands, not plugin code. However, it orchestrates a high-risk supply-chain action: adding an external GitHub plugin source and installing multiple third-party plugins without any visible integrity/provenance controls, then reloading to activate them. Treat this as a supply-chain execution risk and verify the specific plugin versions/commits and their integrity before installation.
Purpose and capabilities mostly align with plugin maintenance, but the skill is not low-risk because it installs and updates third-party plugins from a GitHub-backed marketplace and explicitly chains trust into other plugins. This is best classified as suspicious/medium-high risk supply-chain behavior rather than confirmed malware.