Security audit
UI Whatsynaptor
Security checks for vulnerabilities and agentic risk
Overview
This appears to be a real UI branding plugin, but it deserves review because its installer may loosen Control UI file permissions with sudo and its injected script changes UI settings beyond simple branding.
Use this only if you are comfortable with a global Control UI branding patch. Before installing, inspect the shell script, avoid approving chmod a+rw, back up dist/control-ui/index.html, test in a non-production profile, and verify that disabling the plugin removes its injected assets.
Static analysis
No suspicious patterns detected.
