Back to plugin

Security audit

Overleaf

Security checks for vulnerabilities and agentic risk

Overview

The plugin matches its Overleaf purpose, but its path handling can let an agent run git or compile actions outside the intended project folder, while also using local Overleaf credentials.

Use this plugin only in a dedicated Overleaf projects directory, keep credentials tightly scoped, and review changes before pushing. The main issue to watch is that the current code does not visibly prevent tool parameters from escaping the intended project folder.

Static analysis

No suspicious patterns detected.