Security context
The review model covers package scripts, install hooks, shell execution, process spawning, network requests, filesystem access, environment variables, dependencies, and detected licenses. Current listing pages identify observable capabilities and clearly mark checks that have not been independently run.
Static signalsManifest, scripts, imports, dependencies, and repository files.
Install behaviorCommands, hooks, build steps, and requested system capabilities.
Human contextIntended behavior, disclosure quality, issue history, and maintainer evidence.
Important limits
Automated signals cannot prove that a plugin is safe, future-compatible, or free from hidden behavior. Scores can become stale after repository changes. Always review source, pin versions when possible, and test in a disposable profile first.