plugin-manifest-schema — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited plugin-manifest-schema (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Define plugin manifest schema.
import { z } from 'zod';
export const pluginManifestSchema = z.object({
name: z.string().regex(/^[a-z0-9-]+$/),
version: z.string().regex(/^\d+\.\d+\.\d+/),
description: z.string(),
main: z.string().default('index.js'),
author: z.string().optional(),
license: z.string().optional(),
engines: z.object({
app: z.string().optional(),
node: z.string().optional(),
}).optional(),
dependencies: z.record(z.string()).optional(),
hooks: z.array(z.string()).optional(),
permissions: z.array(z.string()).optional(),
});
export type PluginManifest = z.infer<typeof pluginManifestSchema>;~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.