← Back to Clusters

Security Enhancements for Zip Handling

This cluster focuses on improving security measures related to zip file extraction and plugin scanning to prevent vulnerabilities.

13 PRs
security security plugins Representative: #10705
# Title Author Created GitHub
7317 fix(security): harden zip extraction and hook token comparison daem0ndev 2026-02-02 View
7616 Harden zip extraction against path traversal lawyered0 2026-02-03 View
9529 security(archive): validate entries against path traversal (Zip Slip) leszekszpunar 2026-02-05 View
10530 fix: tighten skill scanner false positives and add vm module detection abdelsfane 2026-02-06 View
10559 feat(security): add plugin output scanner for prompt injection detection DukeDeSouth 2026-02-06 View
10705 security: extend skill scanner to detect threats in markdown skill definitions rep Alex-Alaniz 2026-02-06 View
11032 fix(security): block plugin install/load on critical source scan findings coygeek 2026-02-07 View
13012 Security: detect invisible Unicode in skills and plugins (ASCII smuggling, Tr... agentwuzzi 2026-02-10 View
13894 feat(security): add manifest scanner for SKILL.md trust analysis jdrhyne 2026-02-11 View
17502 feat: normalize skill scanner reason codes and trust messaging ArthurzKV 2026-02-15 View
18819 Improve skill scanner with additional dangerous pattern detection OneZeroEight-ai 2026-02-17 View
20266 feat: skills-audit — Phase 1 security scanner for installed skills theMachineClay 2026-02-18 View
20796 fix(security): OC-22 prevent Zip Slip and symlink following in skill packaging aether-ai-agent 2026-02-19 View