Verune

Plugin

security-watchdog

> Automatic security scanner for Claude Code plugins — detects new or updated extensions at session start and scans them for prompt injection, malicious hook scripts, and data exfiltration. ## The Problem LLM extension ecosystems are a novel attack surface. Traditional security tooling does not cover two threats unique to AI extensions: - **Host attacks** — hook scripts run shell commands automatically on session start, with full user privileges - **Mind attacks** — skill and command files are injected directly into the model's reasoning context, enabling prompt injection No existing security scanner understands these threat classes. Security Watchdog is purpose-built for them. ## How It Works ``` You run: /plugin install someone/new-plugin ↓ Next session starts (SessionStart hook fires) ↓ check-new-plugins.sh diffs installed_plugins.json against a snapshot from the previous session ↓ New/updated plugin detected ↓ Injects into session context: "SECURITY WATCHDOG ALERT: forge@forge was installed. Run /scan-plugin forge@forge before proceeding." ↓ Claude runs /scan-plugin, reads all plugin files, applies security checks, and reports findings ``` The snapshot is updated on detection — each change event fires the alert exactly once.

Analysed
Last observed

What the code does

  • Runs hooks automatically Hooks that execute without being called explicitly.

Having a capability is not wrongdoing; many tools need these to do their job. It tells you what to check before you install.

This is public metadata, not a safety certification or complete assessment. Static analysis cannot establish what a tool does at runtime.

Risk

Sign in to see this tool's overall risk level and what drives it. Free.

Sign in to see the risk level

Coverage

Complete static analysis

How coverage is measured

Detailed report

2 findings from automated static analysis of the latest version, with severities and explanations.

Sign in to view detailed report

Using this tool across your team? We can assess your whole inventory.

Request an inventory assessment