Back to plugin

Security audit

Diffs

Security checks for vulnerabilities and agentic risk

Overview

This plugin coherently provides a read-only diff viewer and temporary PNG/PDF renderer without evidence of hidden or unrelated behavior.

Install if you want agents to create shareable diff views or rendered diff files. Be aware that diff contents are temporarily stored for the configured TTL, viewer URLs include bearer-style tokens, and enabling remote viewer access or a public viewer base URL makes those token URLs reachable outside the local machine.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

Detected: suspicious.obfuscated_code

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
dist/assets/viewer-runtime.js:1
Evidence
var Hc=Object.defineProperty;var Ym=Object.getPrototypeOf;var Km=Reflect.get;var Gc=e=>{throw TypeError(e)};var Om=(e,t,n)=>t in e?Hc(e,t,{enumerable:!0,configu...