| SAS-v2.1 pre-install audit |
|---|
| unexpected code execution, identity privilege abuse, data exfiltration | unexpected code execution, data exfiltration, human approval gap | data exfiltration, memory context poisoning, human approval gap |
|---|
| missing license, broad permissions, shell without guardrails | missing license, broad permissions, shell without guardrails | missing license, broad permissions, network without allowlist |
|---|
| Permission review, Network, Secrets, Command | Permission review, Network, Command | Permission review, Network, Command |
|---|
| | 65% | 65% |
|---|
| Source & provenance |
|---|
| 1Password/onepassword-operator | github/awesome-copilot/tree/main/skills/git-commit | anthropics/claude-code/tree/main/plugins/plugin-dev/skills/mcp-integration |
|---|
| 2026-03-28 | 2026-02-04 | 2026-02-04 |
|---|
| Risk & trust |
|---|
| No explicit signals | runs shell, writes files | network access |
|---|
| repository clone, local runtime dependencies | registry access, remote metadata pull, runtime dependencies may be required | registry access, remote metadata pull, runtime dependencies may be required |
|---|
| Install & compatibility |
|---|
| Universal | Claude, Codex, Cursor, Universal | Claude, Codex, Cursor, Universal |
|---|
| script-backed | registry-install | registry-install |
|---|
|
|---|
| Community |
|---|
| 608 | 20.6K | |
|---|