If you discover that a plugin in this registry is or has become malicious, report it immediately:
- Open a GitHub issue titled "Security: [plugin-id] -- suspected malicious plugin"
- Do not include the full exploit details in the public issue
- Email security@kaijinlab.com with the details (use "Ogma Plugin Security" in the subject)
We aim to remove a confirmed malicious plugin from the registry within 24 hours of verification.
- The plugin entry is removed from
plugins.jsonimmediately - The plugin directory is preserved (renamed to
plugins/quarantine/<id>/) for forensic review - Users who installed the plugin are notified via a release note
This policy covers plugins hosted in this repository. We do not control third-party plugins installed outside of this registry.