Back to plugin

Security audit

8080.ai

Security checks for vulnerabilities and agentic risk

Overview

This 8080.ai integration is mostly coherent, but it installs startup hooks that can force raw tool output into assistant replies, which weakens the stated safety filtering.

Review before installing if you are comfortable giving this plugin an 8080.ai API key, sending project prompts and attachments to 8080.ai, and allowing it to start remote build actions after user selections. Be especially cautious with sensitive project content because the plugin tries to preserve exact remote responses and may reduce assistant-side filtering.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.