Security & Trust Model

Plugins run with the same reach as the assets they carry — a skill can instruct the agent, a command expands into a prompt, a hook (once the engine loads them) runs a shell command. Treat installing a plugin like running someone's code. This document states exactly what our two tiers do and do not promise.

What the tiers mean

✅ Verified

The plugin's source is committed in this repository under plugins/. Consequences:

  • Every change is a pull request, reviewed by a code owner (see CODEOWNERS) and gated on CI (scripts/validate.py).
  • /plugin update pulls this repo's latest reviewed HEAD.
  • The trust statement is: the AtomCode team has read this code at this commit.

🌐 Community

The catalog entry points at an external repository the author controls, pinned to a tag or commit. Consequences:

  • A maintainer reviewed that pinned revision at the time it was added or bumped.
  • We do not review what the author pushes afterward. The pin is the boundary of our review.
  • /plugin update cannot move you past the pin. Advancing a community pin requires a maintainer to merge a PR that changes it — at which point the new revision is reviewed.

The honest version, in one sentence: a Community listing means "a maintainer looked at revision X", not "we vouch for this author forever". If that distinction matters for your threat model, prefer Verified plugins or read the pinned source yourself before installing.

Pinning is mandatory for community plugins

A community entry must pin tag or commit. A bare branch or unpinned URL is rejected by scripts/validate.py and will not be merged — an unpinned listing would let upstream change under reviewed-looking cover, which breaks the promise above.

What we check mechanically

scripts/validate.py runs locally and in CI on every PR. It enforces:

  • catalog parses; tiers are valid; verified ⇒ in-tree, community ⇒ pinned;
  • no path traversal in inline sources (mirrors the engine's own guard);
  • name hygiene so on-disk names match catalog names;
  • a warning when a plugin declares asset types the current engine cannot yet load (so we never ship a dead asset behind a verified badge).

Mechanical checks are necessary, not sufficient. Human review is the other half (GOVERNANCE.md).

Reporting a vulnerability

Found a malicious or vulnerable plugin — in this repo or a community upstream we link to?

  1. Do not open a public issue with exploit details.
  2. Email the maintainers at security@atomcode.dev (or open a private security advisory on the repo host if available).
  3. Include the plugin name, the catalog entry, and the affected revision.

We will pull or unpin the listing while we investigate. Verified plugins can be removed from the tree outright; community listings are delisted by removing their catalog entry.