Skip to main content

Plugin Directory Security Policy

Security boundaries for listings, installation guidance, and reports

Directory boundary

The directory does not execute plugin code and does not certify listed repositories. Public metadata and catalog inclusion are discovery evidence, not a security review.

Before installation, inspect the repository, release provenance, dependency changes, scripts, requested permissions, network access, and handling of local files or credentials. Use an isolated environment when evaluating unfamiliar code.

Responsible reporting

Send security concerns to support@deepseekharnessai.com with the affected plugin and non-sensitive reproduction details. Do not include active credentials, exploit data from real users, or private customer information.