Security & Trust Model
Plugins run with the same reach as the assets they carry — a skill can instruct the agent, a command expands into a prompt, a hook (once the engine loads them) runs a shell command. Treat installing a plugin like running someone's code. This document states exactly what our two tiers do and do not promise.
What the tiers mean
✅ Verified
The plugin's source is committed in this repository under plugins/.
Consequences:
- Every change is a pull request, reviewed by a code owner (see
CODEOWNERS) and gated on CI (scripts/validate.py). /plugin updatepulls this repo's latest reviewed HEAD.- The trust statement is: the AtomCode team has read this code at this commit.
🌐 Community
The catalog entry points at an external repository the author controls,
pinned to a tag or commit. Consequences:
- A maintainer reviewed that pinned revision at the time it was added or bumped.
- We do not review what the author pushes afterward. The pin is the boundary of our review.
/plugin updatecannot move you past the pin. Advancing a community pin requires a maintainer to merge a PR that changes it — at which point the new revision is reviewed.
The honest version, in one sentence: a Community listing means "a maintainer looked at revision X", not "we vouch for this author forever". If that distinction matters for your threat model, prefer Verified plugins or read the pinned source yourself before installing.
Pinning is mandatory for community plugins
A community entry must pin tag or commit. A bare branch or
unpinned URL is rejected by scripts/validate.py and will not be merged —
an unpinned listing would let upstream change under reviewed-looking
cover, which breaks the promise above.
What we check mechanically
scripts/validate.py runs locally and in CI on every PR. It enforces:
- catalog parses; tiers are valid; verified ⇒ in-tree, community ⇒ pinned;
- no path traversal in inline sources (mirrors the engine's own guard);
- name hygiene so on-disk names match catalog names;
- a warning when a plugin declares asset types the current engine cannot yet load (so we never ship a dead asset behind a verified badge).
Mechanical checks are necessary, not sufficient. Human review is the other
half (GOVERNANCE.md).
Reporting a vulnerability
Found a malicious or vulnerable plugin — in this repo or a community upstream we link to?
- Do not open a public issue with exploit details.
- Email the maintainers at security@atomcode.dev (or open a private security advisory on the repo host if available).
- Include the plugin name, the catalog entry, and the affected revision.
We will pull or unpin the listing while we investigate. Verified plugins can be removed from the tree outright; community listings are delisted by removing their catalog entry.