Security audit
Overleaf
Security checks for vulnerabilities and agentic risk
Overview
The plugin matches its Overleaf purpose, but its path handling can let an agent run git or compile actions outside the intended project folder, while also using local Overleaf credentials.
Use this plugin only in a dedicated Overleaf projects directory, keep credentials tightly scoped, and review changes before pushing. The main issue to watch is that the current code does not visibly prevent tool parameters from escaping the intended project folder.
Static analysis
No suspicious patterns detected.
