Security audit
OpenTalk2HTML-NotMD Plugin
Security checks for vulnerabilities and agentic risk
Overview
This HTML plugin is mostly purpose-aligned, but it silently auto-approves broad HTML-related permissions and can expose raw file contents despite claiming compression.
Treat this as a review-required plugin. Install only if you are comfortable with it changing permission decisions for HTML-related requests and exposing full file contents to the agent. Prefer a revised release that uses exact permission allowlists, asks before granting permissions, restricts file reads to intended HTML files inside the workspace, and makes its compression behavior accurate.
Static analysis
No suspicious patterns detected.
