Commit graph

2 commits

Author SHA1 Message Date
Alessandro
30315f5227 Reduce plugin scanner false positives
Calibrate scanner prompts around demonstrated risk instead of the mere presence of common plugin capabilities. Treat scoped credentials, network calls, filesystem access, subprocesses, prompts, and generated assets as expected behavior when they match the declared plugin purpose, while keeping warnings and failures for ambiguity, unsafe handling, concealment, exploitability, or purpose mismatch.

Add regression coverage for the rendered scanner prompt so this calibration is preserved.
2026-05-21 04:02:43 +02:00
frdel
6515626242 refactor - plugin names and builtin plugins 2026-03-10 22:20:53 +01:00
Renamed from plugins/plugin_scan/webui/plugin-scan-checks.json (Browse further)