[External Plugin]: installguard #4812
Copy link
Copy link
Open
Labels
external-pluginPublic external plugin submissionPublic external plugin submissionneeds-review:HIGHContributor reputation check flagged HIGH riskContributor reputation check flagged HIGH riskready-for-reviewSubmission passed intake validation and is ready for maintainer reviewSubmission passed intake validation and is ready for maintainer review
Description
Activity
🔴 Contributor Reputation Check: HIGH risk
Check Risk Profile HIGH Credential audit NONE Maintainers: please review this contributor before merging.
See the workflow run for full details.
Automated check powered by AGT.- addedneeds-review:HIGHContributor reputation check flagged HIGH riskContributor reputation check flagged HIGH riskexternal-pluginPublic external plugin submissionPublic external plugin submissionready-for-reviewSubmission passed intake validation and is ready for maintainer reviewSubmission passed intake validation and is ready for maintainer review
on Oct 9, 2026 ⚠️ External plugin intake passed with spec warningsThis submission passed blocking quality checks and is ready for maintainer review, but it has non-blocking Agent Plugins spec compliance warnings.
View workflow run · Download full quality gate logs
- Plugin: installguard
- Repository: https://github.com/griches/installguard-copilot
- Ref:
v1.0.0 - SHA:
0fd5b5080f209c6c50b121e87144d754d8dfcb3f
Reviewer signals
These are non-blocking heuristics for maintainer review; they are not evidence of misconduct or low quality.
Signal Result Repository age 0 day(s) Repository activity repository is 0 day(s) old; 0 watchers; 0 forks Repository counts 1 stars · 0 watchers · 0 forks · 0 open issues/PRs Quality gate summary
Legend: ✅ pass ·
⚠️ warning · 🛑 failGate Status spec compliance (non-blocking) ⚠️ warningvally lint ✅ pass install smoke test ✅ pass version match ✅ pass ref/sha consistency ✅ pass canvas structure ⚪ not_run - spec compliance: warning
- vally lint: pass
- install smoke test: pass
- version match: pass
- ref/sha consistency: pass
- canvas structure: not_run
- overall: pass
spec compliance output (
⚠️ warning)Agent Plugins v1.0.0 manifest warnings: - $schema should be "https://agent-plugins.org/schemas/1.0.0/plugin.schema.json" - top-level field "category" is not part of Agent Plugins v1.0.0 - top-level field "commands" is not part of Agent Plugins v1.0.0 - top-level field "hooks" is not part of Agent Plugins v1.0.0 - schema validation: manifest must have required property '$schema' - schema validation: manifest must NOT have additional properties - schema validation: manifest must NOT have additional properties - schema validation: manifest must NOT have additional propertiesvally lint output (✅ pass)
0 skill(s) lintedinstall smoke test output (✅ pass)
Install smoke test succeeded. Verified /tmp/external-plugin-quality-TXk454/copilot-home/.copilot/installed-plugins/external-plugin-intake/installguard/plugin.json.Version match output
- v1.0.0: matched version "1.0.0" at "plugin.json". - 0fd5b5080f209c6c50b121e87144d754d8dfcb3f: matched version "1.0.0" at "plugin.json".Ref/SHA consistency output
source.ref "v1.0.0" resolves to the same commit as source.sha "0fd5b5080f209c6c50b121e87144d754d8dfcb3f".Canvas structure output
Canvas structure gate skipped because plugin is not tagged with "canvas".Canonical external.json payload
{ "name": "installguard", "description": "Looks up every new package before Copilot installs it: holds made-up names, typosquats, days-old releases and curl-into-shell for your answer, and lets the rest through.", "version": "1.0.0", "author": { "name": "Gary Riches", "url": "https://github.com/griches" }, "repository": "https://github.com/griches/installguard-copilot", "license": "MIT", "keywords": [ "security", "supply-chain", "npm", "pypi", "cargo", "typosquatting", "slopsquatting", "guard", "hooks" ], "source": { "source": "github", "repo": "griches/installguard-copilot", "ref": "v1.0.0", "sha": "0fd5b5080f209c6c50b121e87144d754d8dfcb3f" } }
Metadata
Metadata
Assignees
Labels
external-pluginPublic external plugin submissionPublic external plugin submissionneeds-review:HIGHContributor reputation check flagged HIGH riskContributor reputation check flagged HIGH riskready-for-reviewSubmission passed intake validation and is ready for maintainer reviewSubmission passed intake validation and is ready for maintainer review
Plugin name
installguard
Short description
Looks up every new package before Copilot installs it: holds made-up names, typosquats, days-old releases and curl-into-shell for your answer, and lets the rest through.
GitHub repository
griches/installguard-copilot
Plugin path inside the repository
No response
Ref to review
v1.0.0
Commit SHA to review
0fd5b5080f209c6c50b121e87144d754d8dfcb3f
Version
1.0.0
License identifier
MIT
Author name
Gary Riches
Author URL
https://github.com/griches
Homepage URL
No response
Keywords
security
supply-chain
npm
pypi
cargo
typosquatting
slopsquatting
guard
hooks
Additional notes for reviewers
A
preToolUsehook plus one/installguardcommand; no skills, agents or MCP servers.When Copilot is about to run a shell command that adds a package the project does not already have (npm, PyPI, crates.io, RubyGems), the hook asks that package's public registry about it and answers
askwith a reason if something is flagged: a name that is not on the registry, a lookalike of a popular package, a package or release that is days old, very low downloads, or a download piped into a shell. Otherwise it prints nothing, so Copilot's own approval applies unchanged; it never answersallow.What it runs and contacts is listed in the README under "What it does on your machine", and in PRIVACY.md: the only hosts are the registries themselves plus api.npmjs.org, pypistats.org and api.deps.dev, and the only thing sent is the package name and version. No telemetry, no account, no model calls.
Needs Node 18+ on the PATH; macOS and Linux (the hooks are
bashentries only, so nothing runs on Windows yet).dist/is committed and CI fails if it is out of date withsrc/. Tested on Copilot CLI 1.0.93.Submission checklist