Plugin Directory Security Policy
Security boundaries for listings, installation guidance, and reports
Directory boundary
The directory does not execute plugin code and does not certify listed repositories. Public metadata and catalog inclusion are discovery evidence, not a security review.
Before installation, inspect the repository, release provenance, dependency changes, scripts, requested permissions, network access, and handling of local files or credentials. Use an isolated environment when evaluating unfamiliar code.
Responsible reporting
Send security concerns to support@deepseekharnessai.com with the affected plugin and non-sensitive reproduction details. Do not include active credentials, exploit data from real users, or private customer information.