Back to plugin

Security audit

Insight Module Plugin

Security checks for vulnerabilities and agentic risk

Overview

This observability plugin matches its stated purpose, but it can expose sensitive agent prompts, tool data, and other plugin hook data in ways users should review carefully.

Install only if you are comfortable with an observability plugin seeing agent activity. Keep captureContent disabled for privacy-sensitive work, be cautious with the NODE_OPTIONS preload because it traces provider SDK content, and point OTLP only at a collector you control. Also review gateway logs, since wrapped action hooks can print raw event/context/result data.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

No suspicious patterns detected.