Marketplace Security: Safe-to-Run verification benchmark for curated MCP servers & plugins
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức phù hợp với người mới
- 18/100
Hướng nghiên cứu
This issue is a third-party pitch for an external Safe-to-Run audit URL, not a scoped change in the marketplace repo. There are no files, tests, or badge specs named. Start by reading the marketplace contribution and plugin-curation docs in this repository and any existing security or listing policy. Done would mean maintainers deciding whether to adopt an audit process and documenting that policy—not implementing the linked engine.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Safe-to-Run Security Verification for Curated MCP Plugins
Hello melodic-software team,
As a marketplace aggregating community skills, hooks, and MCP servers for Claude Code, verifying the safety profile of contributed plugins is critical for user trust.
Developers installing third-party MCP servers onto their local machines risk exposing host filesystems, shell execution surfaces, and credential stores.
We built an automated Safe-to-Run Assessment Engine that verifies:
- Filesystem Confinement: Checks whether file tools enforce workspace boundary jailing.
- Command Injection Risks: Detects unparameterized shell concatenation.
- Secret Redaction: Confirms that API keys and environment secrets are not leaked in tool responses.
- Action Safety: Flags ungated destructive mutations.
You can run automated safety audits on candidate plugins at:
👉 GENESIS Safe-to-Run Verification Engine
We would be glad to offer this automated assessment framework to help establish verification badges for marketplace submissions!
- Ngôn ngữ chính
- Shell
- Star
- 22
- Fork
- 2
- Merge trung bình
- 5 giờ 4 phút
- Pull request đã merge (30 ngày)
- 825
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của melodic-software/claude-code-plugins
-
good first issue needs-triage priority: medium
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
melodic-software/claude-code-plugins#6499 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
needs-human needs-triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 80/100
melodic-software/claude-code-plugins#6496 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
good first issue needs-triage priority: low
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
melodic-software/claude-code-plugins#6390 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
good first issue needs-triage priority: low
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 88/100
melodic-software/claude-code-plugins#6386 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
needs-human needs-triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
melodic-software/claude-code-plugins#6363 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của melodic-software/claude-code-plugins
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
collabnix/awesome-mcp-lists#179 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
electron tech debt
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
Maintainer thường phản hồi trong vòng 1 ngày
-
documentation
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
alunduil/alunduil-chezmoi#870 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
Maintainer thường phản hồi trong vòng 1 ngày
-
package-update
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
oSoWoSo/vOid_Community_repOsitory#268 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày