{"categories":[{"label":"Security","url":"https://skillfed.io/packages/category/security/2"},{"label":"Quality Assurance","url":"https://skillfed.io/packages/category/software-development-quality-assurance/3"}],"enrichment":{"capability":"Lints, verifies, and gates plugins, skills, MCP servers, and packages in CI workflows to detect security risks before release.","skillfed_tags":["ai-agent-security","supply-chain-gating","ci-integration"],"use_cases":["Gate plugin and skill releases in CI by running `plugin-scanner verify` before publishing to a marketplace.","Scan third-party MCP server packages for supply-chain risks before integrating them into an AI agent environment.","Lint custom agent plugins and extensions to detect secret exposure or unsafe patterns before committing to a repository.","Automate pre-release security checks for npm, PyPI, or other package ecosystems using supply-chain scanning.","Explain specific package vulnerabilities or risk signals for a given package version and ecosystem."],"what_it_does":"plugin-scanner is a linting and verification tool designed for maintainers and CI workflows to analyze plugins, skills, MCP servers, and marketplace packages before release. It evaluates supported artifacts for security risks including secret exposure, prompt injection, unsafe commands, and malicious package patterns\u2014the same threat surface that the broader HOL Guard runtime protection addresses, but at the pre-release stage rather than at execution time.\n\nThe tool integrates into CI pipelines and publish workflows to gate ecosystem packages with structured rule metadata and side-effect-free analysis. It depends on eight runtime packages including cryptography, keyring, requests, and rich for output formatting. It is actively maintained, supports Python 3.10 through 3.14, and carries no known vulnerabilities.","worth_installing":"Yes. plugin-scanner is a focused, actively maintained CI tool for pre-release security analysis of AI agent ecosystem packages. It has low install friction, permissive licensing, no known vulnerabilities, and fills a specific maintainer/CI role complementary to runtime protection. Install it if you maintain plugins, skills, or MCP servers and want automated security gating before release."},"id":"plugin-scanner","links":{"html":"https://skillfed.io/packages/plugin-scanner","md":"https://skillfed.io/packages/plugin-scanner.md","pypi":"https://pypi.org/project/plugin-scanner/"},"maintenance":{"status":"active"},"meta":{"latest_release":"2026-07-18","license_spdx":"Apache-2.0","license_treatment":"permissive","name":"plugin-scanner","python_support":"supports_current","summary":"Lint, verify, and gate plugin ecosystems for maintainers, CI, and publish workflows."},"popularity":{"monthly_downloads":165354,"position":10524,"tier":"top_15000"},"security":{"n_vulnerabilities":0},"version":"2.0.1116"}
