Vetting offerings on this website #117
SamuraiBuddha
started this conversation in
General
Replies: 2 comments 1 reply
|
That sounds concerning, thanks for sharing. The templates and scripts eventually run in supervision of us, we are liable for almost each permission we give to the agent. It is still considered risky even if the script passes safety checks as prompt injection has increased to a great extent in last couple of months. Please carefully review prompts or even scripts which you are completely unaware of. Can you please share the specific template/script such that everyone (including the maintainers) are now aware of that, this would help everyone. I am sure someone will inspect it and verify if something unsafe was included. |
0 replies
|
I loaded several… and its been so long since I did that, that I don’t remember which ones. I just stopped using the plugin marketplace and stick to local mcp usage. Thank you for getting back to me.
Thank you,
Jordan P. Ehrig, Sr.
CEO, Director of Services
ebicinc.com
[C]: (407)234-3445
***@***.***> ***@***.***
From: Manan Jariwala ***@***.***>
Sent: Sunday, January 25, 2026 2:24 PM
To: davila7/claude-code-templates ***@***.***>
Cc: Jordan Paul Ehrig ***@***.***>; Author ***@***.***>
Subject: Re: [davila7/claude-code-templates] Vetting offerings on this website (Discussion #117)
That sounds concerning, thanks for sharing.
The templates and scripts eventually run in supervision of us, we are liable for almost each permission we give to the agent. It is still considered risky even if the script passes safety checks as prompt injection has increased to a great extent in last couple of months. Please carefully review prompts or even scripts which you are completely unaware of.
Can you please share the specific template/script such that everyone (including the maintainers) are now aware of that, this would help everyone. I am sure someone will inspect it and verify if something unsafe was included.
—
Reply to this email directly, view it on GitHub <#117 (comment)> , or unsubscribe <https://github.com/notifications/unsubscribe-auth/ASI4K6Y4S4477XMOFFOT5MT4IUJ33AVCNFSM6AAAAACKB5I5W6VHI2DSMVQWIX3LMV43URDJONRXK43TNFXW4Q3PNVWWK3TUHMYTKNJZHE4DANI> .
You are receiving this because you authored the thread. <https://github.com/notifications/beacon/ASI4K63LSOVW6PSMG5TVPLD4IUJ33A5CNFSM6AAAAACKB5I5W6WGG33NNVSW45C7OR4XAZNRIRUXGY3VONZWS33OINXW23LFNZ2KUY3PNVWWK3TUL5UWJTQA5YEL2.gif> Message ID: ***@***.*** ***@***.***> >
|
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Do you guys have a security review for these plugins, mcps, agents, hooks, etc? Never had a problem like this before installing this marketplace and loading up some of these tools... I came out this morning to see my computer acting on its own, trying to delete my Autodesk Docs folders... I have since reformatted, but I wanted to bring this to your attention. This has happened to other marketplaces on claude that they have found malicious code. I think you might want to rethink letting users create their own and they need to have a thorough security review before you post them on your marketplace. I appreciate your effort to bring this to the masses as much as possible and give us an easy way to access these tools, but as always a couple bad players ruin it for everybody. Let me know if you have any questions as to what happened.
All reactions