Security audit
Multilingual Semantic Bridge Plugin
Security checks for vulnerabilities and agentic risk
Overview
The plugin's code, manifest, and runtime instructions are coherent with its stated purpose: it inspects user prompts and (when heuristics match) prepends a small system context to improve multilingual/vector retrieval; it does not request secrets or perform external network calls.
This plugin appears to do what it says: it watches user prompts and may prepend a small system context to improve multilingual/technical retrieval. It does not ask for keys or reach out to external services. Before installing: (1) keep debug disabled in production because debug logs can include promptPreview and session identifiers; (2) test in a staging agent to confirm the injected system context changes behavior in acceptable ways; (3) review your logging/retention policies if you enable debug for troubleshooting; and (4) note the minor package version mismatch in package.json vs registry metadata (cosmetic). If you need stricter privacy, avoid enabling debug and audit logs where this plugin is active.
Static analysis
No suspicious patterns detected.
